Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.3
CVE-2026-76998

A security vulnerability has been detected in SourceCodester Simple Online Food Ordering System 1.0. The impacted element is an unknown function of t…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-76997

A weakness has been identified in SourceCodester Simple Online Food Ordering System 1.0. The affected element is an unknown function of the file /adm…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-75140

jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolled resource consumption vulnerability in XmlTreeBuilder that allows remote attac…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.5
CVE-2026-63043

Relative Path Traversal vulnerability in Apache InLong. Arbitrary file read from the Agent host filesystem. This issue affects Apache InLong: from 2…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.1
CVE-2026-63042

Files or Directories Accessible to External Parties vulnerability in Apache InLong. Any user who can authenticate to the manager can create, modify a…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.4
CVE-2026-63044

Server-Side Request Forgery (SSRF) vulnerability in Apache InLong.  Any authenticated user (no admin role required) can cause the InLong Manager serv…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.1
CVE-2026-63040

Files or Directories Accessible to External Parties vulnerability in Apache InLong. StreamSource performs no authorization check, any authenticated u…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to injec…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-63038

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This allows an attacker to injec…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-63037

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. This appears to allow SQL inject…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-63016

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow upload of non-official packag…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.4
CVE-2026-19611

A flaw was found in WildFly Elytron. Password hashing and verification normalize input with Unicode NFKC, which can collapse fullwidth characters to …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.3
CVE-2026-76996

A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.0
CVE-2026-76993

A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executi…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-76991

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Perf…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.5
CVE-2026-73220

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide ren…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.5
CVE-2026-63490

Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateL…

Patch available
Fix from $4,900 2026-08-20
Unclassified HIGH 7.8
CVE-2026-61898

The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-co…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.8
CVE-2026-61897

An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It chan…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.9
CVE-2026-55558

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the ser…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 8.2
CVE-2026-49825

lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing `…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.6
CVE-2026-44725

EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2…

Patch available
Fix from $4,000 2026-08-20
Vios HIGH 8.8
CVE-2026-16932

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR env…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20
Vios HIGH 7.5
CVE-2026-16928

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20
Vios HIGH 7.0
CVE-2026-16927

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) rac…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20
Vios CRITICAL 9.1
CVE-2026-16926

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special el…

Fix available
Fix from $5,750 2026-08-20
Vios HIGH 7.8
CVE-2026-16925

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20
Vios HIGH 7.5
CVE-2026-16924

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory o…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20
Vios HIGH 7.8
CVE-2026-16923

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20
Vios HIGH 7.0
CVE-2026-16922

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) r…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-20