Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.9
CVE-2026-19755

NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath value…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.8
CVE-2026-18420

Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arb…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-75910

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an au…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.8
CVE-2026-72861

The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-iss…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.0
CVE-2026-9033

An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, inc…

No fix yet
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-77148

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 5.9
CVE-2026-75514

BunkerWeb is an open-source, next-generation Web Application Firewall. Prior to 1.6.13, the blacklist, greylist, and antibot modules in src/common/co…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-72854

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes its new buffer size using an…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.8
CVE-2026-72852

hank-ai/darknet sizes a convolutional layer's weight and output heap buffers by multiplying configuration fields taken from a .cfg file in unchecked …

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-66788

A flaw was found in Lighthouse. A remote attacker, by compromising a spoke cluster, can exploit a vulnerability where the destination namespace for r…

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.7
CVE-2026-66787

A flaw was found in the lighthouse component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability stems from insufficient valida…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-66785

A flaw was found in Submariner. This vulnerability allows a malicious cluster (spoke) to redirect network traffic from other connected clusters (peer…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-66002

Frappe is a full-stack web application framework. Prior to 15.115.0 and 16.27.0, the public request-data web form and PersonalDataDownloadRequest cla…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 8.5
CVE-2026-66001

Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in frappe/integrations/oauth2.py…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-63654

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.bulk_workflow_approval endpoi…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-63003

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.9, page duplication lacks an…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.1
CVE-2026-62315

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/client.py checks a dictionary sup…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-54624

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, render_object_structure i…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-54622

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the copy_plugins endpoint…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-53587

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-53586

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-53585

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-53583

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing to build Git functionality i…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-53569

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_as_seen endpoints in frappe/de…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 8.6
CVE-2026-50190

Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/controller/visitor/BookmarkLis…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-43678

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 11-byte frame sent after a com…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-19683

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a third-party DDNS service, authe…

No fix yet
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-19586EPSS 5%

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insuf…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-77036

A vulnerability was found in elunez eladmin up to 2.7. The impacted element is the function EmailController/AliPayController/GeneratorController/GenC…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.4
CVE-2026-77031

A vulnerability has been found in Tenda CH22 1.0.0.1. The affected element is the function formcreateFileName of the file /goform/formcreateFileName.…

No fix yet
Fix from $4,900 2026-08-20