Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.4 CVE-2026-23561 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23560 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23559 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23556 When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the … Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-58151 varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mappi… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-58146 There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised in… No fix yet Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27464 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27463 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27462 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV dri… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.1 CVE-2026-14261 A vulnerability in the Xerte Online Tools allows for authentication bypass and remote code execution via reinstallation through the /setup/ folder, e… Patch available Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-12116 A vulnerability in the Xerte Online Tools allows for RCE through the antivirus binary path in the tools server settings, which can be changed to a PH… Patch available Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-56291 KEVEPSS 15% Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to… Forms 2.4.1+ Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-5955 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Inrove Software and Internet Services BiEticare… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.3 CVE-2026-2342 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OceanicSoft Informatics Systems Ltd. ValeApp al… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-15158 The Blocksy Companion plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.1.46 via the save_attachmen… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.8 CVE-2026-14245 The miniOrange OTP Login, Verification and SMS Notifications plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Acc… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.1 CVE-2026-47826 The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.… Bosh Cli 7.10.4+ Fix from $2,3002026-07-09 CRITICAL 10.0 CVE-2026-54782 CoreWCF is a port of the service side of Windows Communication Foundation (WCF) to .NET Core. Prior to 1.8.1 and 1.9.1, CoreWCF SAML 1.1 and SAML 2.0… Patch available Fix from $2,3002026-07-08 CRITICAL 9.6 CVE-2026-15113 Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially perform a sandbox escape via … Chrome 150.0.7871.115+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-52200 An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint … Mitigation only Fix from $2,3002026-07-08 CRITICAL 9.1 CVE-2026-55471 HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, org.hl7.fhir.utilities.Xslt… Hl7 Fhir Core 6.9.10+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-44024 Fluentd collects events from various data sources and writes them to files, RDBMS, NoSQL, IaaS, SaaS, Hadoop and so on. Prior to 1.19.3, Fluentd allo… Fluentd 1.19.3+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-31309 Improper authorization in the /tequilapi/config/user endpoint of Mysterium Node from v1.21.1-rc0 before v1.36.0 allows an unauthenticated attacker to… Patch available Fix from $2,3002026-07-08 CRITICAL 9.0 CVE-2026-54527 JupyterLab Git is a Git extension for JupyterLab. From 0.30.0b3 before 0.54.0, the PlainTextDiff.ts createHeader() method passes Git filenames direct… Jupyterlab Git 0.54.0+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-8801 Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.… Moveit Transfer 2025.0.8 / 2025.1.4+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-8649 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affec… Moveit Transfer 2025.0.7 / 2025.1.3+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-29009 U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in nfs_readlink_reply() (net/nfs-common.c) when CONFIG_CMD_NFS is enabled, allowin… U Boot 2026.04+ Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-9074 IBM API Connect 10.0.8.0 through 10.0.8.9 and 12.1.0.0 through 12.1.0.3 contains an unauthenticated SQL injection vulnerability in the password reset… Api Connect 10.0.8.10 / 12.1.1.0+ Fix from $2,3002026-07-08 CRITICAL 9.3 CVE-2026-59702 repomix contains a server-side request forgery vulnerability in the POST /api/pack endpoint that allows unauthenticated attackers to make arbitrary o… Patch available Fix from $2,3002026-07-08 CRITICAL 9.8 CVE-2026-3144 IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials which could allow an attacker to gain unauthorized access to the application befor… Api Connect 12.1.1.0+ Fix from $2,3002026-07-08