Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-15689

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2025-15688

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.1
CVE-2025-15637

Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.0
CVE-2026-77067

The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file im…

Patch available
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.0
CVE-2026-77066

The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig(…

Patch available
Fix from $4,000 2026-08-20
Enterprise Linux MEDIUM 6.5
CVE-2026-73196

A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key…

Fix: 4.13.3+
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-77026

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforc…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-73199

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending …

No fix yet
Fix from $4,000 2026-08-20
Enterprise Linux HIGH 7.5
CVE-2026-73198

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitr…

Fix: 4.13.3+
Fix from $4,900 2026-08-20
Enterprise Linux HIGH 7.5
CVE-2026-73197

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/m…

Fix: 4.13.3+
Fix from $4,900 2026-08-20
Enterprise Linux CRITICAL 9.1
CVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se…

No fix yet
Fix from $5,750 2026-08-20
Enterprise Linux HIGH 8.1
CVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti…

Fix: 4.13.3+
Fix from $4,900 2026-08-20
Unclassified HIGH 7.8
CVE-2026-18917

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-77014

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-76610

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing una…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-14952

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional f…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.0
CVE-2026-14951

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-14950

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-14949

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to cr…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.8
CVE-2026-14948

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pl…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.2
CVE-2026-14947

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extra…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.2
CVE-2026-14946

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code executio…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-76569

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-76565

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.6
CVE-2026-76564

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.6
CVE-2026-75948

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.6
CVE-2025-14601

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.1
CVE-2026-71368

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operation…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.1
CVE-2026-14163

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable sn…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2025-14602

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to ac…

No fix yet
Fix from $4,000 2026-08-20