Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-77641

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() …

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-77639

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.9
CVE-2026-77638

Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the o…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.8
CVE-2026-76023

Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the rendere…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.8
CVE-2026-76022

Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.8
CVE-2026-76021

Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.5
CVE-2026-76020

Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HT…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.1
CVE-2026-76019

Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and le…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.9
CVE-2026-77587

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.0
CVE-2026-77584

Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.8
CVE-2026-76018

Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.8
CVE-2026-76017

Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via cra…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-75484

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR,…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 8.7
CVE-2026-74836

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded nu…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.7
CVE-2026-73137

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.8
CVE-2026-73040

Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-71485

Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.hea…

Patch available
Fix from $5,750 2026-08-20
Unclassified MEDIUM 5.8
CVE-2026-70654

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources an…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-70651

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 8.4
CVE-2026-69242

libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoad…

Patch available
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-67567

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease cu…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-67446

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster befo…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-67445

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLin…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.2
CVE-2026-53804

OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execut…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-19755

NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath value…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.8
CVE-2026-18420

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arb…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-75910

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an au…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.8
CVE-2026-72861

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-iss…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.0
CVE-2026-9033

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, inc…

No fix yet
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-77148

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_…

No fix yet
Fix from $5,750 2026-08-20