Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.3
CVE-2026-78154

A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/a…

No fix yet
Fix from $4,900 2026-08-24
Unclassified MEDIUM 5.3
CVE-2026-78148

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggm…

No fix yet
Fix from $4,000 2026-08-24
Unclassified HIGH 7.3
CVE-2026-78147

A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml…

No fix yet
Fix from $4,900 2026-08-23
Unclassified MEDIUM 6.3
CVE-2026-78144

A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown funct…

No fix yet
Fix from $4,000 2026-08-23
Unclassified HIGH 7.3
CVE-2026-78143

A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file reside…

No fix yet
Fix from $4,900 2026-08-23
Unclassified MEDIUM 6.3
CVE-2026-78142

A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_…

No fix yet
Fix from $4,000 2026-08-23
Unclassified HIGH 7.4
CVE-2026-78141

A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of th…

No fix yet
Fix from $4,900 2026-08-23
Unclassified HIGH 7.5
CVE-2026-9769

justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBu…

No fix yet
Fix from $4,900 2026-08-23
Unclassified MEDIUM 6.1
CVE-2026-8630

justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements s…

No fix yet
Fix from $4,000 2026-08-23
Unclassified CRITICAL 9.8
CVE-2026-8445

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a…

No fix yet
Fix from $5,750 2026-08-23
Unclassified CRITICAL 9.8
CVE-2026-7808

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive s…

No fix yet
Fix from $5,750 2026-08-23
Unclassified MEDIUM 6.1
CVE-2026-77088

justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blan…

No fix yet
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.1
CVE-2026-74793

justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent pr…

No fix yet
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.1
CVE-2026-6827

justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve…

No fix yet
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.1
CVE-2026-5751

justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom Sanitizat…

No fix yet
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.1
CVE-2026-5389

justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre c…

No fix yet
Fix from $4,000 2026-08-23
Unclassified CRITICAL 9.8
CVE-2026-5388

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Ma…

No fix yet
Fix from $5,750 2026-08-23
Unclassified HIGH 7.5
CVE-2026-4671

justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate…

No fix yet
Fix from $4,900 2026-08-23
Unclassified CRITICAL 9.9
CVE-2026-78155

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

No fix yet
Fix from $5,750 2026-08-23
Unclassified MEDIUM 5.4
CVE-2026-78115

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_…

No fix yet
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.3
CVE-2026-78112

A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.ph…

No fix yet
Fix from $4,000 2026-08-23
Unclassified HIGH 8.5
CVE-2026-10053

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

No fix yet
Fix from $4,900 2026-08-23
Unclassified HIGH 7.1
CVE-2026-77115

Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them.

No fix yet
Fix from $4,900 2026-08-23
Unclassified HIGH 7.4
CVE-2026-78063

A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. Th…

No fix yet
Fix from $4,900 2026-08-23
Unclassified HIGH 7.3
CVE-2026-78062

A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the …

No fix yet
Fix from $4,900 2026-08-23
Unclassified MEDIUM 6.3
CVE-2026-78061

A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of …

Patch available
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.3
CVE-2026-78057

A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the comp…

No fix yet
Fix from $4,000 2026-08-23
Unclassified MEDIUM 6.3
CVE-2026-78056

A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some un…

No fix yet
Fix from $4,000 2026-08-23
Unclassified HIGH 7.8
CVE-2026-78136

chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py.

Patch available
Fix from $4,900 2026-08-23
Unclassified MEDIUM 5.3
CVE-2026-78051

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies…

No fix yet
Fix from $4,000 2026-08-23