Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.8
CVE-2026-53528

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authen…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-53527

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.7
CVE-2026-53509

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-53497

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the o…

No fix yet
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-49849

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administr…

Patch available
Fix from $5,750 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-43980

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, …

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-34836

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for d…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 8.6
CVE-2026-34741

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbi…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-33240

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-31936

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operat…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77811

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions t…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77415

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weakn…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77414

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOw…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77413

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwn…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77354

kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 until 0.142.0, openapi3filter.sliceMapToSlice in openapi3filter/req_resp_decoder…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77220

PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a pointer to a stack-local buff…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 7.1
CVE-2026-77219

GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/PGM image loader that allows an attacker to leak heap memory contents by supplyi…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-76905

kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 until 0.141.0, openapi3filter.convertParseError in openapi3filter/validation_erro…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,…

Patch available
Fix from $5,750 2026-08-21
Unclassified MEDIUM 6.1
CVE-2026-69236

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 12.1 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.1
CVE-2026-69235

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.1
CVE-2026-69234

There is a reflected cross site scripting vulnerability in Esri Portal for ArcGIS versions 11.5 and prior which may allow a remote, unauthenticated a…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69233

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged a…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69232

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69231

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, privileged attacker to inject…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-69230

There is a stored cross site scripting issue in Esri Portal for ArcGIS versions 11.5 and prior that may allow a remote, administratively privileged a…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2026-69229

There is an HTML injection vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that allows a remote, authenticated attacker to insert arb…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-69228

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remote, unauthenticated attacker t…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-69225

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 11.5 through 12.0 and earlier that may allow a remote, unauthenti…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-69224

There is an information disclosure vulnerability in Esri Portal for ArcGIS versions 12.0 and earlier that may under difficult to reproduce circumstan…

No fix yet
Fix from $4,000 2026-08-21