Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-53914 In JetBrains Kotlin before 2.4.20 code execution was possible via unsafe deserialization in the build cache metadata Kotlin 2.4.20+ Fix from $2,3002026-06-26 CRITICAL 9.1 CVE-2025-64152 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from … Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.1 CVE-2025-55017 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from … Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-57881 An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-57880 An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-57879 An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-57878 An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabi… Mitigation only Fix from $2,3002026-06-26 CRITICAL 10.0 CVE-2026-2053 The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled inpu… Api Manager 3.1.0.360 / 3.2.0.465+ Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-48930 A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolve… Node.js Patch available Fix from $2,3002026-06-26 CRITICAL 9.4 CVE-2026-40702 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit th… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2025-71338 Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write … Flowise after 3.1.3 Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2025-71336 Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feat… Flowise 3.0.6+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2025-71334 Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflo… Flowise 3.0.6+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2025-71333 Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to … Flowise after 2.2.4 Fix from $2,3002026-06-25 CRITICAL 9.1 CVE-2025-71327 Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to… Flowise No fix yet Fix from $2,3002026-06-25 CRITICAL 9.1 CVE-2026-56445 The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizatio… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-7531 Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server… Wolfssl 5.9.2+ Fix from $2,3002026-06-25 CRITICAL 10.0 CVE-2026-57700 Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-56786 RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buf… Rtklib after 2.4.3 Fix from $2,3002026-06-25 CRITICAL 10.0 CVE-2026-54917 SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceber… Seaweedfs 4.30+ Fix from $2,3002026-06-25 CRITICAL 9.1 CVE-2026-54089 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting wit… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54088 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-50549 Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the… Cursor 3.0+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-50548 Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox gra… Cursor 3.0+ Fix from $2,3002026-06-25 CRITICAL 9.1 CVE-2026-6094 Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supp… Wolfssl 5.9.2+ Fix from $2,3002026-06-25 CRITICAL 9.8 CVE-2026-56123 socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite ad… Socat 1.8.1.2+ Fix from $2,3002026-06-25 CRITICAL 9.4 CVE-2026-55413 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54030 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.5, LibreChat's MCP OAuth implementation does not validate th… Librechat after 0.8.4 Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54849 Unauthenticated SQL Injection in Premmerce Wishlist for WooCommerce <= 1.1.11 versions. Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54843 Unauthenticated SQL Injection in MDTF <= 1.3.7 versions. Mitigation only Fix from $2,3002026-06-25