Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-76641

Expat through 2.8.3 contains an out-of-bounds read vulnerability that allows attackers to trigger memory corruption by processing XML with external e…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.4
CVE-2026-73259

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can send a crafted percent-encoded request path to a deploym…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-73258

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage return or line feed in multipart i…

Patch available
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-73257

Mongoose is an embedded web server and network library. Priro to version 7.22, a remote unauthenticated attacker can send an HTTP request containing …

Patch available
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-73256

Mongoose is an embedded web server and network library. Prior to 7.22, a remote unauthenticated attacker can exploit an HTTP/1.0 reverse-proxy deploy…

Patch available
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-73255

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file can place directory traversal …

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.4
CVE-2026-73254

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger…

Patch available
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-73253

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent d…

Patch available
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-73251

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configure…

Patch available
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-72844

The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment:…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-63495

Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frame…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 8.4
CVE-2026-63388

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when buffer…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.0
CVE-2026-63387

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.2
CVE-2026-63385

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int…

Patch available
Fix from $5,750 2026-08-20
Unclassified HIGH 8.7
CVE-2026-63384

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 8.7
CVE-2026-63383

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c …

Patch available
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.2
CVE-2026-63382

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra…

Patch available
Fix from $5,750 2026-08-20
Unclassified MEDIUM 5.8
CVE-2026-63381

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.7
CVE-2026-63380

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters …

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-63379

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_tr…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.1
CVE-2026-54623

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint …

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.6
CVE-2026-53425

Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML r…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-53424

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.4
CVE-2026-2334

An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "I…

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.1
CVE-2026-77176

A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator ca…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-77025

A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. …

No fix yet
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-77022

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?me…

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 7.3
CVE-2026-77020

A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of th…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.3
CVE-2026-77019

A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/f…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.0
CVE-2026-71492

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registrie…

Patch available
Fix from $4,000 2026-08-20