Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-54494

Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.7
CVE-2026-54493

Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadio…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.1
CVE-2026-54491

Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Netw…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.7
CVE-2026-53549

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /host/db/proxy…

Patch available
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.6
CVE-2026-53548

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-53547

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/expo…

Patch available
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.6
CVE-2026-53546

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket …

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-53545

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-53542

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation en…

Patch available
Fix from $4,900 2026-08-19
Power System S1122 \(9824 22a\) Firmware MEDIUM 6.0
CVE-2026-4937

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with admi…

No fix yet
Fix from $4,000 2026-08-19
Power System S1122 \(9824 22a\) Firmware MEDIUM 6.2
CVE-2026-4936

IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.8
CVE-2026-18849

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrat…

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 8.1
CVE-2026-18544

IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of po…

No fix yet
Fix from $4,900 2026-08-19
I HIGH 8.1
CVE-2026-17015

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-14978

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-14514

IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-12634

The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buff…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 8.1
CVE-2026-12633

The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advert…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-12522

The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.3
CVE-2026-76574

A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/U…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.2
CVE-2026-75593

BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom clie…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-75112

A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashin…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-68901

Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.6
CVE-2026-68900

Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body thro…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 8.7
CVE-2026-68899

Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based …

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-68561

Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpda…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.7
CVE-2026-68560

Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path into the administrator-…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-68559

Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the a…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 8.5
CVE-2026-68558

Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.1
CVE-2026-67189

pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature,…

No fix yet
Fix from $4,000 2026-08-19