Vulnerability index

Browse CVEs

68 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sqlbot HIGH 8.1
CVE-2026-42463

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure …

Fix: 1.8.0+
Fix from $1,950 2026-05-13
Sqlbot HIGH 8.8
CVE-2026-33324

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vul…

Fix: 1.7.1+
Fix from $1,950 2026-05-05
Sqlbot HIGH 8.8
CVE-2026-32950

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a critical SQL Injection vulnerab…

Fix: 1.7.0+
Fix from $1,950 2026-03-20
Sqlbot HIGH 7.5
CVE-2026-32949

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.7.0 contain a Server-Side Request Forgery (SS…

Fix: 1.7.0+
Fix from $1,950 2026-03-20
Sqlbot HIGH 8.8
CVE-2026-32622

SQLBot is an intelligent data query system based on a large language model and RAG. Versions 1.5.0 and below contain a Stored Prompt Injection vulner…

Fix: 1.6.0+
Fix from $1,950 2026-03-19
Jumpserver MEDIUM 6.8
CVE-2026-31864

JumpServer is an open source bastion host and an operation and maintenance security audit system. a Server-Side Template Injection (SSTI) vulnerabili…

Fix: 3.10.22 / 4.10.16+
Fix from $1,600 2026-03-13
Jumpserver MEDIUM 5.0
CVE-2026-31798

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v4.10.16-lts, JumpServer improperly valida…

Fix: 4.10.16+
Fix from $1,600 2026-03-13
Sqlbot MEDIUM 5.9
CVE-2025-15598

A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.…

Fix: after 1.5.1
Fix from $1,600 2026-03-03
Sqlbot MEDIUM 6.3
CVE-2025-15597

A vulnerability has been found in Dataease SQLBot up to 1.4.0. This affects an unknown function of the file backend/apps/system/api/assistant.py of t…

Fix: 1.5.0+
Fix from $1,600 2026-03-02
Cordys Crm CRITICAL 9.8
CVE-2025-70981

CordysCRM 1.4.1 is vulnerable to SQL Injection in the employee list query interface (/user/list) via the departmentIds parameter.

Mitigation only
Fix from $2,300 2026-02-12
Sqlbot MEDIUM 6.1
CVE-2025-69285

SQLBot is an intelligent data query system based on a large language model and RAG. Versions prior to 1.5.0 contain a missing authentication vulnerab…

Fix: 1.5.0+
Fix from $1,600 2026-01-21
1panel HIGH 8.4
CVE-2026-23525

1Panel is an open-source, web-based control panel for Linux server management. A stored Cross-Site Scripting (XSS) vulnerability exists in the 1Panel…

Fix: 1.10.34 / 2.0.17+
Fix from $1,950 2026-01-18
1panel HIGH 7.1
CVE-2025-34429

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the web port configuration functionality. The port-chan…

Fix: after 2.0.15
Fix from $1,950 2025-12-10
1panel HIGH 7.1
CVE-2025-34410

1Panel versions 1.10.33 - 2.0.15 contain a cross-site request forgery (CSRF) vulnerability in the Change Username functionality available from the se…

Fix: after 2.0.15
Fix from $1,950 2025-12-10
1panel HIGH 7.5
CVE-2025-66507

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.13 and below allow an unauthenticated attacker to disable…

Fix: 2.0.14+
Fix from $1,950 2025-12-09
1panel MEDIUM 6.5
CVE-2025-66508

1Panel is an open-source, web-based control panel for Linux server management. Versions 2.0.14 and below use Gin's default configuration which trusts…

Fix: 2.0.14+
Fix from $1,600 2025-12-09
Halo MEDIUM 6.5
CVE-2025-14117

A vulnerability has been found in fit2cloud Halo 2.21.10. Impacted is an unknown function. The manipulation leads to cross-site request forgery. The …

No fix yet
Fix from $1,600 2025-12-06
Jumpserver MEDIUM 6.1
CVE-2025-58044

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.19 and v4.10.5, The /core/i18n// end…

Fix: 3.10.19 / 4.10.5+
Fix from $1,600 2025-12-01
Jumpserver HIGH 7.1
CVE-2025-62795

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to v3.10.21-lts and v4.10.12-lts, a low-privi…

Fix: 3.10.21 / 4.10.12+
Fix from $1,950 2025-10-30
Jumpserver HIGH 8.1
CVE-2025-62712

JumpServer is an open source bastion host and an operation and maintenance security audit system. In JumpServer versions prior to v3.10.20-lts and v4…

Fix: 3.10.20 / 4.10.11+
Fix from $1,950 2025-10-30
1panel HIGH 8.8
CVE-2025-56413

OS Command injection vulnerability in function OperateSSH in 1panel 2.0.8 allowing attackers to execute arbitrary commands via the operation paramete…

Mitigation only
Fix from $1,950 2025-09-10
1panel CRITICAL 9.8
CVE-2025-54424

1Panel is a web interface and MCP Server that manages websites, files, containers, databases, and LLMs on a Linux server. In versions 2.0.5 and below…

Fix: 2.0.6+
Fix from $2,300 2025-08-01
Jumpserver CRITICAL 9.8
CVE-2024-40629

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, …

Fix: 3.10.12+
Fix from $2,300 2024-07-18
Jumpserver CRITICAL 9.1
CVE-2024-40628

JumpServer is an open-source Privileged Access Management (PAM) tool that provides DevOps and IT teams with on-demand and secure access to SSH, RDP, …

Fix: 3.10.12+
Fix from $2,300 2024-07-18
1panel CRITICAL 9.8
CVE-2024-39907EPSS 29%

1Panel is a web-based linux server management control panel. There are many sql injections in the project, and some of them are not well filtered, le…

Fix: 1.10.12-lts+
Fix from $2,300 2024-07-18
1panel CRITICAL 9.8
CVE-2024-39911

1Panel is a web-based linux server management control panel. 1Panel contains an unspecified sql injection via User-Agent handling. This issue has bee…

Fix: 1.10.12-lts+
Fix from $2,300 2024-07-18
1panel HIGH 7.5
CVE-2024-34352

1Panel is an open source Linux server operation and maintenance management panel. Prior to v1.10.3-lts, there are many command injections in the pro…

Fix: 1.10.3-lts+
Fix from $1,950 2024-05-14
1panel MEDIUM 5.9
CVE-2024-30257

1Panel is an open source Linux server operation and maintenance management panel. The password verification in the source code uses the != symbol ins…

Fix: 1.10.3-lts+
Fix from $1,600 2024-04-18
Jumpserver CRITICAL 9.9
CVE-2024-29202EPSS 6%

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection v…

Fix: 3.10.7+
Fix from $2,300 2024-03-29
Jumpserver CRITICAL 9.9
CVE-2024-29201EPSS 6%

JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism…

Fix: 3.10.7+
Fix from $2,300 2024-03-29