Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.8
CVE-2026-68508

Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects sele…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.1
CVE-2026-64679

Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-63421

Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compare…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.2
CVE-2026-63135

YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-62316

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_se…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62283

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 thro…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.2
CVE-2026-61824

Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descrip…

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 10.0
CVE-2026-61539

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Ll…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.2
CVE-2026-59989

Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the…

Patch available
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.1
CVE-2026-55185

Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes be…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-55168

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and c…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 7.7
CVE-2026-54457

TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-53656

FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-53572

KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection st…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 8.8
CVE-2026-50538

LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server c…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.5
CVE-2026-45271

Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 valida…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-45099

Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt …

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-44517

Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confi…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 8.0
CVE-2026-31880

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universa…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.0
CVE-2026-31803

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.0
CVE-2026-30890

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro …

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.1
CVE-2026-30865

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboar…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.0
CVE-2026-30826

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing …

Patch available
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-77810

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the co…

No fix yet
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-76876

Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiti…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 8.6
CVE-2026-74252

Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable …

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.1
CVE-2026-67362

Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-67361

Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-67360

Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.7
CVE-2026-67359

Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could suppl…

No fix yet
Fix from $4,900 2026-08-21