Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-59145 Data::Intern::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated slot, reverse and arena indices in si_idx_find. The a… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-59144 Data::RingBuffer::Shared versions before 0.04 for Perl allow a stack buffer overflow via an unvalidated elem_size in ring_read_seq. The attach-time … No fix yet Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-50755 An issue in DayuanJiang next-ai-draw-io 0.4.13 allows a remote attacker to obtain sensitive information via the X-Forwarded-For header value No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59142 Data::HashMap::Shared versions before 0.14 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in shm_str_copy. The atta… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59141 Data::RadixTree::Shared versions before 0.02 for Perl allow an out-of-bounds read via unvalidated node and arena indices in rdx_find_locked. The att… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59140 Data::SortedSet::Shared versions before 0.03 for Perl allow an out-of-bounds read via unvalidated node indices in the rank and min/max query paths. … No fix yet Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-59139 Data::ReqRep::Shared versions before 0.05 for Perl allow an out-of-bounds read via an unvalidated arena offset and length in reqrep_recv_locked. The… Mitigation only Fix from $2,3002026-07-21 CRITICAL 9.6 CVE-2026-16441 In Eclipse OpenJ9 versions up to 0.60, when executing class files where a previously concrete superclass method has been recompiled as abstract, exec… Openj9 0.60.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2016-20096 Linknat VOS3000 and VOS2009 through version 2.1.2.0 contain an unauthenticated SQL injection vulnerability that allows remote attackers to execute ar… No fix yet Fix from $2,3002026-07-21 CRITICAL 9.6 CVE-2026-47416 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 are vulnerable to vertical privilege esc… Patch available Fix from $2,3002026-07-21 CRITICAL 9.6 CVE-2026-47413 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have aprivilege escalation / cross-tenan… Patch available Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-16439 In Eclipse OpenJ9 versions up to 0.60, using -Xtrace to trace method arguments can lead to buffer underflow. Openj9 0.60.0+ Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-47410 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Versions prior to 0.1.4 have an insecure default cryptographic k… Patch available Fix from $2,3002026-07-21 CRITICAL 9.4 CVE-2026-47407 PraisonAI Platform is the platform layer for the PraisonAI multi-agent teams system. Prior to version 0.1.4, the Platform server exposes resources un… Patch available Fix from $2,3002026-07-21 CRITICAL 9.3 CVE-2026-64825 Home Assistant Core before 2026.6.0 contains a path traversal vulnerability that allows unauthenticated attackers to write arbitrary files to any dir… Patch available Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-47396 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's call server exposes a network-facing agent control API without authenti… Patch available Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-47393 PraisonAI is a multi-agent teams system. CVE-2026-44338 (GHSA-6rmh-7xcm-cpxj) documents that PraisonAI ships a code-generator (`praisonai.deploy.api.… Patch available Fix from $2,3002026-07-21 CRITICAL 9.9 CVE-2026-47392 PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` i… Patch available Fix from $2,3002026-07-21 CRITICAL 9.8 CVE-2026-47391 PraisonAI is a multi-agent teams system. Prior to version 4.6.40, PraisonAI's first-party A2A server example exposes an unauthenticated A2A JSON-RPC … Patch available Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28321 SolarWinds Serv-U is affected by a broken access control vulnerability that could allow arbitrary file read and write, which can then be used to esca… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28317 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation. This issue requires … Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28316 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to privilege escalation to a system administr… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28314 SolarWinds Serv-U is affected by an insecure direct object reference vulnerability that leads to an account takeover. User authentication is required… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28313 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to SMTP hijacking leading to arbitrary accoun… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28312 SolarWinds Serv-U is affected by a privilege escalation vulnerability. This would elevate a group’s access to system administrator and allow code exe… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28310 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to escalate their user type to that of a sys… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28309 SolarWinds Serv-U is affected by a broken access control vulnerability that allows a domain administrator to create system administrator accounts. Th… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28308 SolarWinds Serv-U is affected by an insecure direct object reference (IDOR) vulnerability that can lead to remote code execution. Domain administrato… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28307 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain user group to be elevated into an administrator group. The… Serv U 2026.3+ Fix from $2,3002026-07-21 CRITICAL 9.1 CVE-2026-28306 SolarWinds Serv-U is affected by a privilege escalation vulnerability that allows a domain administrator to elevate their privileges to a system admi… Serv U 2026.3+ Fix from $2,3002026-07-21