Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.3
CVE-2026-77392

A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of th…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.8
CVE-2026-76157

Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unau…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.4
CVE-2026-76156

OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execut…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-76155

Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depen…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depe…

No fix yet
Fix from $5,750 2026-08-21
Unclassified HIGH 8.7
CVE-2026-16520

Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77647

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to inc…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.7
CVE-2026-77113

Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary fi…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.7
CVE-2026-77646

A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited thr…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.2
CVE-2026-77645

A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-77644

A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 7.5
CVE-2026-77642

tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.5
CVE-2026-72860

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the desti…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 8.6
CVE-2026-72848

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf ur…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.4
CVE-2026-72846

Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat…

No fix yet
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-72843

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, wh…

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 7.5
CVE-2026-72818

The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-70105

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.7
CVE-2026-69855

Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-69851

Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 10.0
CVE-2026-69836

Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.6
CVE-2026-69558

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 10.0
CVE-2026-69555

Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.5
CVE-2026-69543

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.6
CVE-2026-69519

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.5
CVE-2026-69419

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.6
CVE-2026-69400

Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-68789

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…

No fix yet
Fix from $5,750 2026-08-20