Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-54680 Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer Fluen… Patch available Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-51992 SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries … Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-13697 undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a… Undici 7.29.0 / 8.9.0+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-67191 Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-60113 AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte… Ait Dsn 2.2.2+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-60112 AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o… Ait Gui 2.5.1+ Fix from $2,3002026-07-29 CRITICAL 10.0 CVE-2026-54735 Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in … Prebid Server 4.4.0+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65888 Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user… Gridbox 2.20.2+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65887 Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u… Gridbox 2.20.2+ Fix from $2,3002026-07-29 CRITICAL 9.4 CVE-2026-9177 A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in vers… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL… Gridbox 2.20.2+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65884 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una… Gridbox 2.20.2+ Fix from $2,3002026-07-29 CRITICAL 9.3 CVE-2026-0667 CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of … No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o… Aimy Captcha Less Form Guard after 20.0 Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-14900 The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.0.3 via the js_to… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-14488 The Meta Box AIO plugin for WordPress is vulnerable to Missing Authorization via the template_redirect dispatcher in the MB Frontend Submission exten… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-59243 The FAB auth manager's Azure AD OAuth login defaulted `verify_signature=False` when decoding the ID token, so an attacker able to present a forged or… Apache Airflow Providers Fab 3.7.3+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58185 The Apache Traffic Server intercept plugin has a use-after-free. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 thro… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58179 The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affects Apache Traffic Server: fro… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-58177 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Se… Traffic Server 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-58163 Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing. This issue affects Apache Traffic Server: … Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 10.0 CVE-2026-58162 The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI. This issue affects Apache Traffic Server:… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2025-10656 The Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light plugin for WordPress is vulnerable to Missing Authorization in all versions u… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.3 CVE-2026-58155 Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass. This issue affects Apache Tr… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 10.0 CVE-2026-58150 Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic … Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 10.0 CVE-2026-57834 Apache Traffic Server allows request smuggling if chunked messages are malformed. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.3 CVE-2026-41920 Improper Access Control vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, from 10.0.0 thr… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-33267 Improper Input Validation vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 t… Traffic Server 9.2.15 / 10.1.4+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-18191 VIN-DS783E-E6 developed by Vacron has a Hidden Functionality vulnerability, allowing unauthenticated remote attackers to exploit a specific hidden fu… Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2026-63234 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the manual mark assessmen… No fix yet Fix from $2,3002026-07-29