Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.3
CVE-2026-76761

A vulnerability was identified in chenhg5 cc-connect up to 1.4.1. This affects the function shellExecCommand of the file core/engine.go of the compon…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.3
CVE-2026-76760

A vulnerability was found in chenhg5 cc-connect up to 1.4.1. Affected by this vulnerability is the function Authenticate of the file core/webhook.go.…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.4
CVE-2026-76878

In OpenStack Aodh before 22.0.1, the alarm list API bypasses project scoping when the all_projects query parameter is set to false. The API checks fo…

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-76850

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py r…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-76832

Agno's PythonTools in libs/agno/agno/tools/python.py contains a path traversal vulnerability that allows attackers to read, write, or execute arbitra…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.4
CVE-2026-76591

A security flaw has been discovered in TRENDnet TEW-755AP up to 20260702. This affects the function log_email_server of the file /cgi-bin/email.cgi o…

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76590

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cg…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76589

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the …

No fix yet
Fix from $5,750 2026-08-19
Model Context Protocol Server CRITICAL 9.1
CVE-2026-76404

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating …

Fix: 1.2.1+
Fix from $5,750 2026-08-19
Connect For Kafka HIGH 7.4
CVE-2026-76403

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user positioned in the network path could read or alter all relevant data sent f…

Fix: 2.2.7+
Fix from $4,900 2026-08-19
Connect For Kafka HIGH 8.2
CVE-2026-76402

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API …

Fix: 2.2.7+
Fix from $4,900 2026-08-19
Connect For Kafka MEDIUM 5.9
CVE-2026-76401

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API …

Fix: 2.2.7+
Fix from $4,000 2026-08-19
Connect For Kafka MEDIUM 5.9
CVE-2026-76400

In Splunk Connect for Kafka versions below 2.2.7, an unauthenticated user who can reach the Kafka Connect Representational State Transfer (REST) API …

Fix: 2.2.7+
Fix from $4,000 2026-08-19
Ai Toolkit HIGH 8.1
CVE-2026-76399

In Splunk AI Toolkit versions below 6.0.1, a user who holds the "power" Splunk role could modify app-provided scheduled searches to run arbitrary Sea…

Fix: 6.0.1+
Fix from $4,900 2026-08-19
Ai Toolkit HIGH 8.1
CVE-2026-76397

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could access and delete all relevant data in experiment history, …

Fix: 6.0.0+
Fix from $4,900 2026-08-19
Ai Toolkit HIGH 7.5
CVE-2026-76396

In Splunk AI Toolkit versions below 6.0.0, a user that holds a role with the schedule_search capability could cause a scheduled search to load and de…

Fix: 6.0.0+
Fix from $4,900 2026-08-19
Ai Toolkit HIGH 8.8
CVE-2026-76395

In Splunk AI Toolkit versions below 6.0.0, a user who holds the "power" Splunk role could execute arbitrary code on the Splunk server by loading a mo…

Fix: 6.0.0+
Fix from $4,900 2026-08-19
Ai Toolkit HIGH 8.3
CVE-2026-76394

In Splunk AI Toolkit versions below 6.0.0, a low-privileged user who does not hold the "admin" or "power" Splunk roles could start, stop, and configu…

Fix: 6.0.0+
Fix from $4,900 2026-08-19
Ai Toolkit MEDIUM 5.9
CVE-2026-76393

In Splunk AI Toolkit versions below 6.0.0, a user who can upload models could overwrite a model being uploaded by another user by sending a concurren…

Fix: 6.0.0+
Fix from $4,000 2026-08-19
Ai Toolkit MEDIUM 5.4
CVE-2026-76392

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could obtain predictable or default credentia…

Fix: 6.0.0+
Fix from $4,000 2026-08-19
Ai Toolkit HIGH 8.3
CVE-2026-76391

In Splunk AI Toolkit versions below 6.0.0, a user who does not hold the "admin" or "power" Splunk roles could run searches with system-level privileg…

Fix: 6.0.0+
Fix from $4,900 2026-08-19
Talos Intelligence For Enterprise Security Cloud MEDIUM 5.3
CVE-2026-76390

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the add-on OpenAPI specification…

Fix: 1.0.3+
Fix from $4,000 2026-08-19
Talos Intelligence For Enterprise Security Cloud HIGH 8.8
CVE-2026-76389

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, a user that holds a role with the get_talos_enrichment capability cou…

Fix: 1.0.3+
Fix from $4,900 2026-08-19
Enterprise Security HIGH 8.1
CVE-2026-76388

In Splunk Enterprise Security versions below 8.6.1, a user who holds the ess_analyst Splunk Enterprise Security role could change User and Entity Beh…

Fix: 8.6.1+
Fix from $4,900 2026-08-19
Enterprise Security HIGH 8.1
CVE-2026-76387

In Splunk Enterprise Security versions below 8.6.1, a user who holds a Splunk Enterprise Security role that contains the mc_investigation_read capabi…

Fix: 8.6.1+
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.0
CVE-2026-76375

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could expose sensitive credentials…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.4
CVE-2026-76373

In versions below 2.3.8 of the AD LDAP app for Splunk SOAR, a user who holds a role with permission to run actions could inject crafted input into an…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.6
CVE-2026-76372

In Nmap Scanner versions below 3.0.15, a user who holds a role that can edit, create, or run playbooks in Splunk SOAR could run the scan network acti…

No fix yet
Fix from $4,000 2026-08-19
Soar MEDIUM 6.5
CVE-2026-76366

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (REST) API filtering on playbo…

Fix: 8.6.0+
Fix from $4,000 2026-08-19
Soar MEDIUM 6.5
CVE-2026-76365

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Structured Query Language (SQL) …

Fix: 8.6.0+
Fix from $4,000 2026-08-19