Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-78213 Heptabase developed by Hepta Platforms, Inc. has a Stored Cross-Site Scripting vulnerability. Authenticated remote attackers can inject persistent ma… No fix yet Fix from $4,9002026-08-24 HIGH 7.5 CVE-2026-78212 4MOSAn developed by 4MOSAn Security Technology Co., Ltd. has an Arbitrary File Read vulnerability. Unauthenticated remote attackers can exploit a Rel… No fix yet Fix from $4,9002026-08-24 CRITICAL 9.8 CVE-2026-78211 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malic… No fix yet Fix from $5,7502026-08-24 MEDIUM 6.3 CVE-2026-78185 A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. The impacted element is an unknown function of the file /pages/cust_edit… No fix yet Fix from $4,0002026-08-24 HIGH 7.3 CVE-2026-78182 A security vulnerability has been detected in Shenzhen Gongji Technology XBROTHER Dynamic Environment Monitoring System up to 300R004C00B300. The aff… No fix yet Fix from $4,9002026-08-24 HIGH 7.3 CVE-2026-78181 A weakness has been identified in ractivejs ractive up to 1.4.4. Impacted is the function Ractive#set of the component Keypath Handler. Executing a m… No fix yet Fix from $4,9002026-08-24 HIGH 7.3 CVE-2026-78180 A security flaw has been discovered in alibaba-fusion next up to 1.27.34. This issue affects the function ConfigProvider.getContextProps of the file … No fix yet Fix from $4,9002026-08-24 MEDIUM 6.3 CVE-2026-78179 A vulnerability was identified in rexrainbow phaser3-rex-notes up to 1.80.17. This vulnerability affects the function SetValue of the file plugins/ut… No fix yet Fix from $4,0002026-08-24 MEDIUM 5.3 CVE-2026-19853 NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers can exploit a specific funct… No fix yet Fix from $4,0002026-08-24 MEDIUM 6.1 CVE-2026-19852 NewSiteServer (NSS) developed by CyberTutor has an Arbitrary File Upload vulnerability. Unauthenticated remote attackers can upload arbitrary files, … No fix yet Fix from $4,0002026-08-24 HIGH 8.9 CVE-2026-19200 The Velociraptor verify() VQL function allows a user to verify an artifact for syntatic and other issues. Due to an implementation fault in this VQL … No fix yet Fix from $4,9002026-08-24 HIGH 7.3 CVE-2026-78178 A vulnerability was determined in jQWidgets up to 24.0.1. This affects the function JQXLite.extend/jqxBaseFramework.extend of the file jqwidgets/jqx-… No fix yet Fix from $4,9002026-08-24 HIGH 7.3 CVE-2026-78171 A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $4,9002026-08-24 HIGH 8.8 CVE-2026-78170 A flaw has been found in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formConfigFastDirectionW. Executing… No fix yet Fix from $4,9002026-08-24 CRITICAL 9.9 CVE-2026-78169 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempS… No fix yet Fix from $5,7502026-08-24 CRITICAL 9.8 CVE-2026-78168 A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component … No fix yet Fix from $5,7502026-08-24 CRITICAL 10.0 CVE-2026-78167 A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session… No fix yet Fix from $5,7502026-08-24 MEDIUM 6.3 CVE-2026-78166 A security flaw has been discovered in provectus kafka-ui up to 0.7.2. The affected element is the function executeSmartFilterTest of the file kafka-… No fix yet Fix from $4,0002026-08-24 HIGH 8.2 CVE-2026-78209 exceljs-hardened versions before 5.0.0 fail to neutralize leading equals, plus, minus, or at signs in cell values written to CSV output. Attackers wh… No fix yet Fix from $4,9002026-08-24 HIGH 7.5 CVE-2026-78208 exceljs-hardened before 5.0.0 contains a path traversal vulnerability in the Workbook.addImage() function that fails to validate file paths. Attacker… No fix yet Fix from $4,9002026-08-24 CRITICAL 9.4 CVE-2026-78207 exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or pr… No fix yet Fix from $5,7502026-08-24 HIGH 7.5 CVE-2026-78206 exceljs-hardened before 5.0.0 decompresses all entries from supplied xlsx archives into memory without limits on entry size, total size, or compressi… No fix yet Fix from $4,9002026-08-24 MEDIUM 5.8 CVE-2026-78205 BentoML's outbound connection safeguard (make_safe_connect in _internal/utils/uri.py) blocks private, loopback, and link-local IP addresses but fails… No fix yet Fix from $4,0002026-08-24 MEDIUM 5.4 CVE-2026-78204 Ghostwriter through 7.2.6 does not apply per-object authorization on its report template lint endpoints. RoleBasedAccessControlMixin.test_func return… No fix yet Fix from $4,0002026-08-24 HIGH 7.1 CVE-2026-78203 Ghostwriter before 7.1.2 fails to validate template ownership in the report template swap endpoint, allowing attackers to attach client-scoped templa… No fix yet Fix from $4,9002026-08-24 HIGH 7.3 CVE-2026-78161 A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is the function report_raw_cbor of the file lib/misc/lecp.c of the component LECP … No fix yet Fix from $4,9002026-08-24 MEDIUM 6.3 CVE-2026-78160 A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of … No fix yet Fix from $4,0002026-08-24 MEDIUM 6.3 CVE-2026-78158 A flaw has been found in Open5GS 2.8.0. This vulnerability affects unknown code of the component AMF UEContextReleaseRequest Path Handler. Executing … No fix yet Fix from $4,0002026-08-24 HIGH 7.4 CVE-2026-78157 A vulnerability was detected in Open5GS 2.8.0. This affects the function pcrf_rx_aar_cb of the file src/pcrf/pcrf-rx-path.c of the component Rx AA-Re… No fix yet Fix from $4,9002026-08-24 HIGH 7.4 CVE-2026-78156 A security vulnerability has been detected in Open5GS 2.8.0. Affected by this issue is the function hss_ogs_diam_s6a_air_cb of the file src/hss/hss-s… No fix yet Fix from $4,9002026-08-24