Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Splunk HIGH 8.8
CVE-2026-76254

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, 9.4.14, and 9.3.14, an unauthenticated user could cause another user to dispatch arbitrar…

Fix: 9.3.14 / 9.4.14+
Fix from $4,900 2026-08-19
Splunk HIGH 8.8
CVE-2026-76253

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the schedule_search capability could run arbitr…

Fix: 9.4.14 / 10.0.9+
Fix from $4,900 2026-08-19
Splunk MEDIUM 6.1
CVE-2026-76252

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user into visiting a malicious web…

Fix: 9.4.13 / 10.0.9+
Fix from $4,000 2026-08-19
Splunk HIGH 7.1
CVE-2026-76251

In Splunk Enterprise versions below 10.4.2, 10.2.6, and 10.0.9, a user who does not hold the "admin" or "power" Splunk roles could cause the Splunk A…

Fix: 10.0.9 / 10.2.6+
Fix from $4,900 2026-08-19
Windows App MEDIUM 6.5
CVE-2026-69550

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Fix: 11.3.9+
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-63123

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacms/cli/src/next/vite/cors.ts o…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.4
CVE-2026-59992

Tina is a headless content management system. Prior to next-tinacms-s3 23.0.4, next-tinacms-dos 23.0.4, next-tinacms-azure 14.0.4, and next-tinacms-c…

Patch available
Fix from $4,000 2026-08-19
Ds8900f Firmware MEDIUM 5.4
CVE-2025-36398

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to read or modi…

Fix: after 89.44.25.0
Fix from $4,000 2026-08-19
Ds8900f Firmware HIGH 8.8
CVE-2025-36255

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an authenticated user to create a use…

Fix: after 89.44.25.0
Fix from $4,900 2026-08-19
Ds8900f Firmware HIGH 7.4
CVE-2025-36254

IBM System Storage DS8A00 10.1.3.0 through 10.11.35.0 and IBM DS8900F 89.40.83.0 through 89.44.25.0 could allow an attacker to bypass security authen…

Fix: after 89.44.25.0
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.8
CVE-2026-76827

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper with or delete another cluster…

No fix yet
Fix from $4,000 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76584

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.4
CVE-2026-76583

A vulnerability was identified in TRENDnet TV-IP751WIC 11.03.03. Affected by this vulnerability is an unknown functionality of the file /cgi-bin/admi…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.4
CVE-2026-76582

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected is the function popen/system of the file /cgi-bin/ping.cgi of the component…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.0
CVE-2026-76139

A flaw was found in acm-operator-bundle. The build process for this component downloads and runs a script from a remote source without verifying its …

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.5
CVE-2026-75616

An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configurat…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.7
CVE-2026-75596

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default io.netty.handler.ssl.SniHa…

Patch available
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.1
CVE-2026-75595

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHand…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 7.7
CVE-2026-75569

A flaw was found in mce-operator-bundle. The build process fetches and executes scripts from a remote repository without performing integrity checks,…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-69222

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to 10.27.2, the join filter in src/filters/array.ts compute…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-68555

Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedly resume one allocation from …

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.1
CVE-2026-68553

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.0, an authenticated TURN user can place printf-style format specif…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-68552

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.15.0, an unauthenticated remote client can send a STUN message over T…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.0
CVE-2026-62727

Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Telephony Service allows an authorized attacke…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.7
CVE-2026-61556

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. From 10.26.0 until 10.27.1, the strip_html filter in src/filters/…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.4
CVE-2026-54743

Lemmy is a link aggregator and forum for the fediverse. Prior to lemmy-ui 0.19.19-beta.1, LemmyNet/lemmy-ui renders Markdown in src/shared/markdown.t…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-54741

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, Lemmy blocks new private messages from a sender after th…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-54740

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moderator can remove a higher-rank…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-54739

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, Lemmy's login endpoint in crates/api/api/src/local_user/lo…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-54738

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::realip_remote_addr reads the fir…

Patch available
Fix from $4,000 2026-08-19