Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-75928

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a re…

No fix yet
Fix from $4,000 2026-08-21
Unclassified CRITICAL 10.0
CVE-2026-69502

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-21
Unclassified HIGH 7.5
CVE-2026-54789

mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Rel…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.1
CVE-2026-49114

In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens i…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.5
CVE-2026-22681

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal net…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-75501

A vulnerability in the Calix EXOS firmware for the GS7 XGS (GS5239XG) residential router allows unauthenticated remote attackers to modify NAT port‑f…

Fix unknown
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-77815

to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic li…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-77814

is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without ap…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.4
CVE-2026-77812

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.6
CVE-2026-77087

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebindi…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-63343

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to a…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-63125

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC i…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62941

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction ch…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62940

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62867

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in stora…

No fix yet
Fix from $5,750 2026-08-21
Unclassified HIGH 7.7
CVE-2026-55622

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an att…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.7
CVE-2026-55621

Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where a…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-50278

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` …

Patch available
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48769

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48755

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm le…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48753

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48752

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48751

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block`…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48750

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoin…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48749

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitr…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77806

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to cod…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.2
CVE-2026-75946

A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentiall…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-15580

vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-77780

Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-77028

Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66

No fix yet
Fix from $4,000 2026-08-21