Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-48751

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block`…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48750

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoin…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48749

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitr…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77806

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to cod…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.2
CVE-2026-75946

A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentiall…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-15580

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-77780

Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-77028

Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.6
CVE-2026-76613

Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-lev…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.6
CVE-2026-76612

Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user su…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-76611

Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.0
CVE-2026-75115

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.8
CVE-2026-59654

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects diffe…

No fix yet
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-77776

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/p…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.6
CVE-2026-77775

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in head…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77759

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user …

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-59318

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-59279

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default …

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-19848

The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allow…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-17559

The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass gl…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-16650

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-15150

The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77769

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboar…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77768

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAc…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-77767

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role,…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77763

The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from …

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-77761

A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into t…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2026-77686

A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handl…

Patch available
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-77683

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-77086

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to …

No fix yet
Fix from $5,750 2026-08-21