Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2024-51312 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. No fix yet Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-53595 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{h… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2024-51313 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2024-51311 The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-63767 ktransformers through 0.6.3, fixed in commit def0f93, contains an unauthenticated pickle deserialization vulnerability that allows remote attackers t… Patch available Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-63766 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.1 CVE-2026-44231 RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10, 6.0.0 and above, prior to 6.0.3 contain an informa… Request Tracker 5.0.10 / 6.0.3+ Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-16337 Improper authorization in the ToolGroupResource and RoleAjax REST/DWR endpoints in dotCMS dotCMS 21.02 through 26.06.22-03 on all platforms allows a … Patch available Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-64193 Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose pars… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.1 CVE-2026-62414 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac… Mitigation only Fix from $2,3002026-07-20 CRITICAL 10.0 CVE-2026-61900 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-61425 Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, poten… No fix yet Fix from $2,3002026-07-20 CRITICAL 10.0 CVE-2026-61424 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vuln… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-60034 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS … No fix yet Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-60032 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authentic… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-12341 This vulnerability impacts all versions of IdentityIQ and allows an unauthenticated attacker unauthorized access to protected APIs and data due to im… Identityiq 8.3+ Fix from $2,3002026-07-20 CRITICAL 9.3 CVE-2026-39878 Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.9 CVE-2026-54051 Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`San… Patch available Fix from $2,3002026-07-20 CRITICAL 9.1 CVE-2026-41521 xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within … Xrdp 0.10.6.1+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-41252 xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when o… Xrdp 0.10.6.1+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-35048 The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.9 CVE-2026-51027 An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.1 CVE-2026-46428 lettre is a a mailer library for Rust. Starting in version 0.10.1 and prior to version 0.11.22, an inverted-boolean bug in lettre's `boring-tls` inte… Patch available Fix from $2,3002026-07-20 CRITICAL 10.0 CVE-2026-46412 @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UT… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.0 CVE-2026-35198 HeyForm is an open-source form builder. Prior to version 3.0.0-rc.7, a stored cross-site scripting (XSS) vulnerability in the form builder allows a l… Patch available Fix from $2,3002026-07-20 CRITICAL 9.1 CVE-2026-28220 Wazuh is a free and open source platform used for threat prevention, detection, and response. Prior to version 4.14.5, issues in the Cluster Distribu… Wazuh 4.14.5+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-63071 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements for Implementations can crea… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-62183 Improper Privilege Management vulnerability in Apache Syncope. When: * the all-Java user workflow adapter is configured, or * the Flowable user wor… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-57308 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Syncope. An administrator with adequate… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2026-53421 Improper Isolation or Compartmentalization vulnerability in Apache Syncope. An administrator with adequate entitlements can achieve remote code ex… Syncope 4.0.7 / 4.1.2+ Fix from $2,3002026-07-20