Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-56260 Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path param… Crawl4ai 0.8.7+ Fix from $2,3002026-07-12 CRITICAL 10.0 CVE-2026-61447 PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python code without… Mitigation only Fix from $2,3002026-07-11 CRITICAL 9.9 CVE-2026-61445 PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation a… Mitigation only Fix from $2,3002026-07-11 CRITICAL 9.8 CVE-2026-60090 PraisonAI before 4.6.78 fails to validate the caller-controlled dimension argument in the PGVector and Cassandra knowledge-store create_collection() … Patch available Fix from $2,3002026-07-11 CRITICAL 9.1 CVE-2026-56372 ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the magnify operation that allows attackers to read out of bounds memory… Imagemagick 7.1.2-19+ Fix from $2,3002026-07-11 CRITICAL 9.8 CVE-2026-57827 Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unaut… Rsfiles\! 1.17.12+ Fix from $2,3002026-07-11 CRITICAL 9.1 CVE-2026-15089 vulnerability in Drupal Commerce guest registration allows . This issue affects Commerce guest registration versions: *.*. No fix yet Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-20744 The charging station websocket endpoint accepts connections without proper authentication, which could lead to privilege escalation. Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.9 CVE-2026-14480 OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application store… Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-11913 vulnerability in Drupal Mother May I allows . This issue affects Mother May I versions: *.*. No fix yet Fix from $2,3002026-07-10 CRITICAL 9.2 CVE-2026-55884 Tilt defines dev environments as code for microservice apps on Kubernetes. From 0.20.8 through 0.37.3, the Tilt HUD HTTP server registers handlers on… Patch available Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-12535 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Formatter Field allows Object Injection. This … Formatter Field 2.0.0+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-10768 Missing Authorization vulnerability in Drupal LocalGov Workflows allows Forceful Browsing. This issue affects LocalGov Workflows versions: from 0.0.0… Localgov Workflows 1.6.0+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-9726 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Obj… Alternativecommerce 2.1.17+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-57807 Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Security Software Pvt Ltd. OAuth Single Sign On - SSO (OAuth Cli… Mitigation only Fix from $2,3002026-07-10 CRITICAL 10.0 CVE-2026-57216 RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication c… Rabbitmq Server 4.2.6+ Fix from $2,3002026-07-10 CRITICAL 10.0 CVE-2026-57211 RabbitMQ is a messaging and streaming broker. Prior to 4.1.11 and 4.2.6 on Windows, the RabbitMQ management plugin static file handler rabbit_mgmt_wm… Rabbitmq Server 4.2.6+ Fix from $2,3002026-07-10 CRITICAL 9.3 CVE-2026-55879 OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page… Patch available Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-12761 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) plugin for WordPress is vulnerable to authentication bypass leading to … Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.1 CVE-2026-57158 FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incompl… Freerdp 3.28.0+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-57156 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in upd… Freerdp 3.28.0+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-61459 MCP Server Kubernetes before 3.9.0 contains an argument injection vulnerability in structured tools (kubectl_get, kubectl_describe, kubectl_delete) t… Mcp Server Kubernetes 3.9.0+ Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-5801 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Semtek Informatics Software Consulting Trade Lt… Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.6 CVE-2026-59151 Prowler is a cloud security platform. Prior to 5.30.3, Prowler's SAML authentication flow trusted the email domain asserted in a SAMLResponse when de… Patch available Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-2397 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows… Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.2 CVE-2026-58492 grav-plugin-database is the database plugin for Grav CMS. Prior to 1.2.0, the PDO::tableExists method interpolates its table argument directly into a… Patch available Fix from $2,3002026-07-10 CRITICAL 9.1 CVE-2026-51119 An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.9 CVE-2026-55500 9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, … Patch available Fix from $2,3002026-07-10 CRITICAL 9.3 CVE-2026-15143 A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Sc… Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.1 CVE-2026-61444 PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated int… Mitigation only Fix from $2,3002026-07-10