Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-63087 Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sen… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-46621 Yamcs is a mission control framework. Prior to 5.12.7, the Yamcs script evaluation engine for Python algorithms dynamically compiled and evaluated us… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-46562 Yamcs is a mission control framework. Prior to 5.12.7, the Nashorn ScriptEngine used to evaluate user-supplied JavaScript algorithm text in yamcs-cor… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-45568 zrok is software for sharing web services, files, and network resources. Prior to 2.0.3, zrok's Python SDK ProxyShare Flask proxy route accepts an ab… Zrok 2.0.3+ Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-44632 Yamcs is a mission control framework. Prior to 5.12.7, a server-side code injection vulnerability existed in the Yamcs algorithm evaluation engine or… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-3031 Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated … No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-44596 Yamcs is a mission control framework. Prior to 5.12.7, the authentication endpoint POST /auth/token in yamcs-core, handled by yamcs-core/src/main/jav… Yamcs 5.12.7+ Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-59866 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, Kiota emitted x-ms-kiota-info clientClassName and clientNamespaceNa… Patch available Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-59865 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.d… Patch available Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-59864 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.5, `kiota plugin add` and `kiota plugin generate` (with `-t APIPlugin`… Patch available Fix from $2,3002026-07-16 CRITICAL 9.3 CVE-2026-54733 The Microsoft 365 and Microsoft Entra ID Plugins for Moodle provide Office 365 and Azure Active Directory integration for Moodle. Prior to 4.5.6, 5.0… Patch available Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-45695 Kopia is a cross-platform backup tool for Windows, macOS, and Linux with fast incremental backups, client-side end-to-end encryption, compression, an… Patch available Fix from $2,3002026-07-16 CRITICAL 9.1 CVE-2026-14890 SGLang uses an expert-parallel backup subsystem that exposes a ZeroMQ PULL socket on a routable network interface that does not contain authenticatio… Sglang after 0.5.14 Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-56453 HCL DFXAnalytics is affected by an Account Takeover via Response Manipulation vulnerability. A remote attacker can intercept and alter the contents o… Dfxanalytics after 3.0 Fix from $2,3002026-07-16 CRITICAL 9.0 CVE-2026-11386 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2023-49900 An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2023-49899 An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channe… Mitigation only Fix from $2,3002026-07-16 CRITICAL 9.6 CVE-2026-22752 Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serv… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.2 CVE-2026-15925 Improper TLS hostname verification in Snowflake Connector for Python versions prior to 4.7.1 and 3.18.1 may have allowed a network-positioned attacke… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-12492 The Happy Coders OTP Login for WooCommerce WordPress plugin before 2.8 does not verify that a one-time password was actually validated before authent… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-15013 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass via SAML Signature Algorithm Confusion in all version… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2026-55652 Wekan is open source kanban built with Meteor. Prior to 9.46, header-login with HEADER_LOGIN_TRUSTED_IPS uses getRequestIp() in server/lib/headerLogi… Patch available Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-55445 Qinglong is a timed task management platform supporting Python3, JavaScript, Shell, and Typescript. Prior to 2.20.1, the init guard middleware in bac… Patch available Fix from $2,3002026-07-15 CRITICAL 9.6 CVE-2026-54458 WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin.… Patch available Fix from $2,3002026-07-15 CRITICAL 9.2 CVE-2026-52893 Wekan is open source kanban built with Meteor. Prior to 9.32, the Wekan Accounts.onCreateUser hook in server/models/users.js merges OIDC logins into … Patch available Fix from $2,3002026-07-15 CRITICAL 9.9 CVE-2026-52891 Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passe… Patch available Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-30623 LiteLLM 1.18.10 contains a remote code execution vulnerability in its MCP server creation functionality. The application allows users to add MCP serv… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-30618 xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker … Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.1 CVE-2026-26718 A Cross-Site Request Forgery (CSRF) vulnerability exists in the xxl-job-admin web application v.3.0.0 that allows an attacker to perform unauthorized… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2025-65720 An issue in Open Source GPT Researcher v3.3.7 allows attackers to execute arbitrary commands on a victim system via user interaction with a crafted H… Mitigation only Fix from $2,3002026-07-15