Vulnerability index

Browse CVEs

1,648 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Trueconf Server CRITICAL 9.0
CVE-2026-72530 KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, …

Fix: 5.3.9.10013 / 5.3.9.10015+
Fix from $5,750 2026-08-19
Trueconf Server CRITICAL 9.8
CVE-2026-72529 KEV

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, …

Fix: 5.3.9.10013 / 5.3.9.10015+
Fix from $5,750 2026-08-19
Mlflow CRITICAL 9.3
CVE-2026-64849 KEVEPSS 8%

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated…

Fix: 3.15.0+
Fix from $5,750 2026-08-17
Zimbra Collaboration Suite HIGH 8.9
CVE-2026-73570 KEV

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP…

Fix: 10.1.20+
Fix from $1,950 2026-08-13
Windows 10 1607 HIGH 7.0
CVE-2026-68820 KEV

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $1,950 2026-08-11
Adaptive Security Appliance Software HIGH 8.6
CVE-2026-20349 KEV

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T…

No fix yet
Fix from $1,950 2026-08-11
Metabase CRITICAL 10.0
CVE-2026-72898 KEVEPSS 10%

Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access …

Fix: 0.58.24 / 0.59.21+
Fix from $2,300 2026-08-10
macOS CRITICAL 9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…

Fix: 14.8.9 / 15.7.9+
Fix from $2,300 2026-08-06
N Central HIGH 8.1
CVE-2026-18577 KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Fix: 2026.3+
Fix from $1,950 2026-08-02
N Central HIGH 7.4
CVE-2026-18556 KEV

Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-centra…

Fix: after 2026.1
Fix from $1,950 2026-08-01
Vcenter Server CRITICAL 9.8
CVE-2026-59310 KEV

VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i…

Fix: 8.0 / 9.0.2.0100+
Fix from $2,300 2026-07-30
Secure Firewall Management Center MEDIUM 5.3
CVE-2026-20316 KEV

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

Fix: after 10.0.1
Fix from $1,600 2026-07-29
Teamcity CRITICAL 9.8
CVE-2026-63077 KEVEPSS 12%

In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

Fix: 2025.11.7 / 2026.1.3+
Fix from $2,300 2026-07-27
Velocloud Orchestrator CRITICAL 10.0
CVE-2026-16812 KEV

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…

Fix: 5.2.3.14 / 6.1.3.4+
Fix from $2,300 2026-07-27
Multi Domain Security Management CRITICAL 9.8
CVE-2026-16232 KEVEPSS 73%

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati…

Patch available
Fix from $2,300 2026-07-22
WordPress CRITICAL 9.8
CVE-2026-63030 KEVEPSS 96%

WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n…

Fix: 6.9.5 / 7.0.2+
Fix from $2,300 2026-07-17
WordPress MEDIUM 5.9
CVE-2026-60137 KEVEPSS 73%

WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c…

Fix: 6.8.6 / 6.9.5+
Fix from $1,600 2026-07-17
Langflow CRITICAL 9.8
CVE-2026-9198 KEVEPSS 19%

IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit…

Fix: 1.10.1+
Fix from $2,300 2026-07-17
Dd Wrt HIGH 8.1
CVE-2021-27137 KEVEPSS 16%

An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat…

Fix: 45724+
Fix from $1,950 2026-07-16
Sma6210 Firmware HIGH 7.2
CVE-2026-15410 KEVEPSS 76%

Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C…

Mitigation only
Fix from $1,950 2026-07-14
Sma6210 Firmware CRITICAL 10.0
CVE-2026-15409 KEVEPSS 74%

A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack…

Mitigation only
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.1
CVE-2026-55040 KEVEPSS 5%

Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-58644 KEVEPSS 45%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-56164 KEVEPSS 22%

Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Windows 10 1607 HIGH 7.8
CVE-2026-56155 KEV

Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall…

Fix: 10.0.14393.9339 / 10.0.17763.9020+
Fix from $1,950 2026-07-14
Sharepoint Server CRITICAL 9.8
CVE-2026-50522 KEVEPSS 77%

Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.

Fix: 16.0.19725.20434+
Fix from $2,300 2026-07-14
Forms CRITICAL 9.8
CVE-2026-56291 KEVEPSS 76%

Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to…

Fix: 2.4.1+
Fix from $2,300 2026-07-09
Coldfusion CRITICAL 10.0
CVE-2026-48282 KEVEPSS 99%

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul…

Mitigation only
Fix from $2,300 2026-06-30
Page Builder Ck CRITICAL 9.8
CVE-2026-56290 KEVEPSS 83%

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl…

Fix: 3.6.0+
Fix from $2,300 2026-06-29
Langflow HIGH 8.4
CVE-2026-55255 KEVEPSS 29%

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili…

Fix: 1.9.1+
Fix from $1,950 2026-06-23