Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-68782

Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-67448

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw Reques…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-67447

Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 8.6
CVE-2026-66800

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-66309

Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 10.0
CVE-2026-65816

Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 10.0
CVE-2026-65801

Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 10.0
CVE-2026-65770

Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthori…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-63509

Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-62834

Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-55894

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.3
CVE-2026-55893

Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFM…

Patch available
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.4
CVE-2026-55769

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened …

Patch available
Fix from $5,750 2026-08-20
Unclassified HIGH 8.5
CVE-2026-55765

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedde…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.4
CVE-2026-55491

BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/pla…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.5
CVE-2026-55015

Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally.

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.1
CVE-2026-55013

Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally.

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-54509

TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns th…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-54508

TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() an…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.5
CVE-2026-54389

Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra proc…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-50192

Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub c…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.3
CVE-2026-49436

LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URL…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.9
CVE-2026-49244

SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a brow…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-49217

Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any u…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.5
CVE-2026-46682

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingI…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-46355

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebu…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.7
CVE-2026-19783

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafte…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.8
CVE-2026-19449

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a vulnerability in cmdnim that may allow an unprivileged local user to executes the payload as root.

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-19448

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decapsulation handler. Successful e…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-19446

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 allows a remote unauthenticated attacker can send a crafted UDP packet to a reachable RPC service, resu…

No fix yet
Fix from $4,900 2026-08-20