Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-53451

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-52889

Formie is a Craft CMS plugin for creating forms. Prior to 3.1.27, Formie can pass request-derived Hidden field defaults such as HTTP User Agent, Refe…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 7.3
CVE-2026-52834

jxl-oxide is a pure Rust implementation of a JPEG XL decoder. Prior to jxl-grid 0.6.2, decoding a crafted JPEG XL image on a 32-bit platform can over…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 8.7
CVE-2026-52792

Algernon is a small self-contained pure-Go web server. Prior to 1.17.9, Algernon on Windows selects a file handler in engine/handlers.go by calling f…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-50149

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is configured with incompatible …

No fix yet
Fix from $4,000 2026-08-19
Command Update HIGH 7.8
CVE-2026-49817

Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Command Update HIGH 7.8
CVE-2026-49816

Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local a…

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-49289

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. In 4.19.2 and 4.20.2, the library permits attacker-controlled XPath…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 8.7
CVE-2026-49283

The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related functionality. Prior to versions 4.19.3, 4.20.2, 5.0.6, and 6.2.1, the HTTPArtifac…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-49255

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm constructs operating system comm…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.1
CVE-2026-49253

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.11.11, electerm uses remote-supplied filenames d…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.0
CVE-2026-48711

SSHFS is a network filesystem client for connecting to SSH servers. From version 1.4 until 3.7.6, SSHFS accepts a bracketed mount source such as [-oP…

Patch available
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-47187

SSHFS is a network filesystem client for connecting to SSH servers. Prior to version 3.7.6, a rogue SFTP server can return absolute symlink targets o…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 7.5
CVE-2026-45742

Gotenberg is a Docker-powered stateless API for PDF files. From 8.10.0 until 8.33.0, the newContext function in pkg/modules/api/context.go starts one…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-45741

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, the IsPublicIP function in pkg/gotenberg/outbound.go does not rejec…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-45274

MyBooks is anebook management web server also known as Talebook. In 3.41.2 and earlier, the SignUp.post handler for POST /api/user/sign_up in webserv…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 8.7
CVE-2026-45273

MyBooks is an ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post handler for POST /api/admin/settings …

Patch available
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.4
CVE-2026-45272

MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the AdminSettings.post han…

Patch available
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-44829

Gotenberg is a Docker-powered stateless API for PDF files. In 8.32.0 and earlier, filename handling in pkg/modules/api/context.go uses filepath.Base …

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.4
CVE-2026-40508

OpenEMR before 8.3.0 contains a stored cross-site scripting vulnerability in the patient portal template import handler that allows authenticated att…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.1
CVE-2026-40507

OpenEMR before 8.3.0 contains a reflected cross-site scripting vulnerability in the patient portal template import handler. The templateHtml GET para…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-32802

Dell PowerPath, version 7.2 through to 8.0 SP1, contains an Improper Privilege Management vulnerability. A low privileged attacker with local access …

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.2
CVE-2026-23501

Dell RecoverPoint for VMs, versions 6.0.3 and 6.0.3.1, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Inj…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.2
CVE-2026-18756

HumHub Community Edition 1.18.4 contains a reflected cross-site scripting vulnerability in the Space membership-request workflow. An attacker can pla…

Patch available
Fix from $4,900 2026-08-19
Unclassified HIGH 7.4
CVE-2026-18526

HumHub Community Edition 1.18.4 and 1.18.4-pl1 contain a stored Cross-Site Scripting (XSS) vulnerability in the oEmbed confirmation rendering workflo…

Patch available
Fix from $4,900 2026-08-19
Vios HIGH 7.5
CVE-2026-16818

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to uncontrolled resource consumption.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Vios HIGH 7.5
CVE-2026-16817

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a NULL pointer dereference.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Vios CRITICAL 9.9
CVE-2026-16816

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralizatio…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios HIGH 8.8
CVE-2026-16814

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a heap buffer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Vios HIGH 7.5
CVE-2026-16706

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19