Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-34048 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal websocket boots… Patch available Fix from $2,3002026-07-07 CRITICAL 9.9 CVE-2026-34047 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, terminal WebSocket boots… Patch available Fix from $2,3002026-07-07 CRITICAL 9.9 CVE-2026-34037 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire a… Patch available Fix from $2,3002026-07-07 CRITICAL 10.0 CVE-2026-57572 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 CRITICAL 9.6 CVE-2026-57571 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename w… Crawl4ai 0.9.0+ Fix from $2,3002026-07-06 CRITICAL 10.0 CVE-2026-54763 Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewa… Traefik 2.11.51 / 3.6.22+ Fix from $2,3002026-07-06 CRITICAL 9.2 CVE-2026-42341 FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerab… Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.9 CVE-2026-34038 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, an authenticated remote … Patch available Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-11405 The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains … Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-9182 Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted fi… Arcgis Server after 12.0 Fix from $2,3002026-07-06 CRITICAL 9.9 CVE-2026-48614 An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in … Mitigation only Fix from $2,3002026-07-06 CRITICAL 10.0 CVE-2026-48316 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.9 CVE-2026-40141 A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the process… Privileged Remote Access 25.3.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-40139 A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authenticati… Privileged Remote Access 25.3.3+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-5268 An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allo… Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2025-53830 Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for … Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2025-53827 ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15… Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.3 CVE-2026-12686 An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted … Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-56140 Improper Input Validation vulnerability in Apache Camel AWS SNS component. The camel-aws2-sns component filters Camel headers through a component-s… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-53913 Improper Authentication, Missing Authentication for Critical Function, Not Failing Securely ('Failing Open') vulnerability in Apache Camel Keycloak C… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-48205 Improper Input Validation, Server-Side Request Forgery (SSRF) vulnerability in Apache Camel DNS component. The camel-dns producers read DNS operatio… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-48204 Improper Input Validation, Improper Access Control vulnerability in Apache Camel in Camel Mongodb Gridfs component. The camel-mongodb-gridfs produce… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-48203 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), Improper Input Validation, Server-Side Request Fo… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-46456 Improper Input Validation vulnerability in Apache Camel AWS2-SQS Component. The camel-aws2-sqs component map inbound message attributes into the Ca… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-46455 Insufficient Session Expiration vulnerability in Apache Camel Keycloak Component. The camel-keycloak security helper KeycloakSecurityHelper.parseAnd… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-46454 Improper Input Validation vulnerability in Apache Camel Cometd Component. The camel-cometd component maps inbound Bayeux (CometD) message headers in… Camel 4.14.8 / 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-43867 Deserialization of Untrusted Data vulnerability in Apache Camel PQC Component. The camel-pqc component persists post-quantum key metadata (KeyMetada… Camel 4.18.3 / 4.21.0+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-40047 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache Camel Docling component. The camel-doclin… Camel 4.18.3+ Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-24014 Apache IoTDB DataNode’s internal RPC interface for creating Trigger instances uses the uploaded Trigger JAR name to build a file path without suffici… Iotdb 2.0.8+ Fix from $2,3002026-07-06 CRITICAL 9.1 CVE-2026-24013 Authentication Bypass by Spoofing vulnerability in Apache IoTDB. Certain Thrift RPC query handlers lack strict validation of the sessionId parameter.… Iotdb 2.0.8+ Fix from $2,3002026-07-06