Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-9103 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/a… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9202 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_A… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9198 KEVEPSS 37% IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit… Langflow 1.10.1+ Fix from $2,3002026-07-17 CRITICAL 9.3 CVE-2026-9586 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-8297 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laborato… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.3 CVE-2026-54496 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.1 CVE-2026-12694 Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.4 CVE-2026-12693 Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-12692 Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Vide… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-60024 Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-51080 libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability. Libpve Storage Perl No fix yet Fix from $2,3002026-07-17 CRITICAL 9.1 CVE-2024-23564 HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server … No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-9810 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator … Mitigation only Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-15982 The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al… Mitigation only Fix from $2,3002026-07-17 CRITICAL 9.1 CVE-2026-62241EPSS 7% clawvet self-hosted API server (apps/api) before 0.7.5 hard-codes a fallback JWT secret ('clawvet-dev-secret-change-me') in auth.ts and ships it as t… Clawvet 0.7.5+ Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-14956 The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val… No fix yet Fix from $2,3002026-07-17 CRITICAL 10.0 CVE-2026-44182 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v… Enterprise Gateway 3.3.0+ Fix from $2,3002026-07-16 CRITICAL 10.0 CVE-2026-44181 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. In v… Enterprise Gateway 3.3.0+ Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-57075 YAML::Syck versions before 1.47 for Perl allow an out-of-bounds read via a signed-char lookup-table index in syck_base64dec. The base64 decoder in t… Patch available Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-53412 Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica… Workplace Desktop 6.5.18 / 6.6.15+ Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-44180 Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers… Enterprise Gateway 3.3.0+ Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-38158 A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-63089 WireGuard Easy through 15.3.0, fixed in commit 66b292b, contains a cryptographically weak one-time link token generation vulnerability that allows un… Patch available Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-15422 The illumos SCTP inbound path performs association lookup for INIT ACK chunks without adequately validating the address parameters carried in the chu… Patch available Fix from $2,3002026-07-16 CRITICAL 9.9 CVE-2026-54526 Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to 3.7.15 and 4.0.6, the allow… Argo Workflows 3.7.15 / 4.0.6+ Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-46515 Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.3, PERM_READ access was sufficient to call fm_list_managers, fm_list_pin… Patch available Fix from $2,3002026-07-16 CRITICAL 9.9 CVE-2026-46512 Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, de… Patch available Fix from $2,3002026-07-16 CRITICAL 10.0 CVE-2026-45336 HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-57074 XML::Bare versions through 0.53 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter stri… Patch available Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-57073 HTML::Bare versions through 0.04 for Perl have an unbounded character lookahead. The parserc_parse function attempts to check for multicharacter str… Patch available Fix from $2,3002026-07-16