Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2026-57898 In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauth… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.2 CVE-2026-15183 Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrat… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.6 CVE-2026-11563 The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper au… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-44761 SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in … Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.9 CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption t… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-27690 Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads t… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-58102 Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-of-bounds read via a long certificate extension OID in hv_exts. When building t… Crypt\ 2.1.3+ Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-62327 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-52533 An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file No fix yet Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-59801 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-51821 SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUser… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51541 OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath si… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-51540 OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing … Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51538 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When th… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51537 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing sh… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51536 In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-58409 ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) … Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.5 CVE-2026-6875EPSS 78% ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an … Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-61500 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of th… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-57433 Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a sign… Storable 3.41+ Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-13221 Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is co… Perl after 5.43.9 Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-6847 Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application expos… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-61498 Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/gen_graphs.php endpoint that allows remote una… Flamingo after 4.12.2 Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-60121 Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection vulnerability in the admin/ajax/ping.php endpoint that allows remote attackers… Flamingo after 4.12.2 Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-40469 Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap… Gawk after 5.4.0 Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-40468 Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating … Gawk after 5.4.0 Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-12257 Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.4 CVE-2026-14934 A Missing Authorization vulnerability in the repository creation functionality in Google Cloud BigQuery, Dataform and Colab Enterprise, in the versio… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-59518 Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection.This issue affects Directorist: from n/a thr… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.3 CVE-2026-59515 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Sergey AIWU ai-copilot-content-generator allows… Mitigation only Fix from $2,3002026-07-13