Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-77413

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwn…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77354

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77220

PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buff…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 7.1
CVE-2026-77219

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplyi…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_erro…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,…

Patch available
Fix from $5,750 2026-08-21
Unclassified MEDIUM 6.1
CVE-2026-69236

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.1
CVE-2026-69235

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.1
CVE-2026-69234

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated a…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69233

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged a…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69232

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69231

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69230

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged a…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2026-69229

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arb…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-69228

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker t…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-69225

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenti…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-69224

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstan…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.8
CVE-2026-68508

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects sele…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.1
CVE-2026-64679

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-63421

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compare…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.2
CVE-2026-63135

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-62316

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_se…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62283

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 thro…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.2
CVE-2026-61824

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descrip…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 10.0
CVE-2026-61539

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Ll…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.2
CVE-2026-59989

Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the…

Patch available
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.1
CVE-2026-55185

Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes be…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-55168

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and c…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 7.7
CVE-2026-54457

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-53656

FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone…

Patch available
Fix from $4,000 2026-08-21