Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-51380 Buffer Overflow vulnerability in Tenda AC10 v3 (firmware V03.03.16.09) allows attackers to cause a permanent Denial of Service (DoS) or potentially e… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.9 CVE-2026-54052 n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with… N8n Mcp 2.56.1+ Fix from $2,3002026-07-15 CRITICAL 10.0 CVE-2026-52887 NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to 2.0.61, NocoBase @nocobase/… Patch available Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-49352 9Router is an AI router & token saver. From 0.2.21 until 0.4.44, 9Router used the hardcoded fallback JWT secret 9router-default-secret-change-me in s… Patch available Fix from $2,3002026-07-15 CRITICAL 10.0 CVE-2026-46339 9Router is an AI router & token saver. From 0.4.30 until 0.4.37, 9Router's src/proxy.js middleware did not protect /api/cli-tools/* and /api/mcp/*, a… Patch available Fix from $2,3002026-07-15 CRITICAL 9.5 CVE-2026-46684 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase enterprise token handling can let TokenFilter#doFilter() … Patch available Fix from $2,3002026-07-15 CRITICAL 9.0 CVE-2026-45534 DataEase is an open source data visualization and analysis tool. Prior to 2.10.23, DataEase Redshift datasource connections can load attacker-control… Patch available Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-46421 The SAP Cloud Application Programming Model is a tool for building enterprise-grade cloud applications, and cap-js/cds-dbs is the monorepo for SQL da… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.6 CVE-2026-62948 OpenWrt is a Linux operating system targeting embedded devices. Prior to 25.12.5, odhcpd writes a DHCPv6 client FQDN option 39 hostname into /tmp/odh… Openwrt 25.12.5+ Fix from $2,3002026-07-15 CRITICAL 9.6 CVE-2026-53513 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the @better-auth/sso plugin's POST /sso/register and POST… Better Auth\/sso 1.6.11+ Fix from $2,3002026-07-15 CRITICAL 9.1 CVE-2026-53512 Better Auth is an authentication and authorization library for TypeScript. Prior to 1.6.11, the legacy oidcProvider and mcp plugins expose OAuth toke… Better Auth 1.6.11+ Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-50562 FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted … Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-14960 Pegatron `Tdelo64.sys` improperly exposes privileged hardware access functionality through the `\\.\TdeIo` device interface. IOCTL handlers including… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.0 CVE-2026-62378 RustFS Console is a web management console for the RustFS distributed file system. From 0.1.7 until 0.1.10, the RustFS Console components/object/prev… Patch available Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-52843 Lightpanda is a headless browser designed for AI and automation. Prior to 0.2.9, Lightpanda fetch() and XMLHttpRequest unconditionally attached sessi… Patch available Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-52842 Lightpanda is a headless browser designed for AI and automation. Prior to 0.3.1, Lightpanda searched for @ across the entire URL string instead of on… Patch available Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-20157 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte… Roomos 11.32.6.0 / 11.39.1.1+ Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-20156 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco RoomOS engineering team has conducted a comprehensive inte… Roomos 11.32.6.0 / 11.39.1.1+ Fix from $2,3002026-07-15 CRITICAL 9.1 CVE-2026-50148 Metabase is an open-source business intelligence and embedded analytics tool. From 1.54.0 until 1.54.24, 1.55.24, 1.56.25, 1.57.19, 1.58.14, 1.59.10,… Metabase 1.54.24 / 1.55.24+ Fix from $2,3002026-07-15 CRITICAL 9.9 CVE-2026-44986 Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from … Patch available Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-61740 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, when LightRAG is deployed with LIGHTRAG_API_KEY set but AUTH_ACCOUN… Patch available Fix from $2,3002026-07-15 CRITICAL 9.3 CVE-2026-61736 LightRAG provides simple and fast retrieval-augmented generation. Prior to 1.5.4, the server defaults to CORS_ORIGINS=* combined with allow_credentia… Patch available Fix from $2,3002026-07-15 CRITICAL 9.1 CVE-2026-43637 Cornac before 2.6.0 contains a path traversal (Tar Slip) vulnerability that allows attackers to write arbitrary files outside the intended cache dire… Patch available Fix from $2,3002026-07-15 CRITICAL 9.6 CVE-2026-61451 The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/… Mitigation only Fix from $2,3002026-07-15 CRITICAL 10.0 CVE-2026-56699 Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to in… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.6 CVE-2026-56400 open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow_origins=* and authenticated … Open Webui 0.3.14+ Fix from $2,3002026-07-15 CRITICAL 9.0 CVE-2026-56398 Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the picture claim URL MIME type i… Open Webui 0.9.5+ Fix from $2,3002026-07-15 CRITICAL 9.5 CVE-2026-13385 An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M… Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-5270 An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-5269 In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operation… No fix yet Fix from $2,3002026-07-14