Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-48751 Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block`… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-48750 Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoin… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-48749 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitr… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.8 CVE-2026-77806 SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to cod… Patch available Fix from $5,7502026-08-21 HIGH 8.2 CVE-2026-75946 A potential security vulnerability has been identified in the OMEN Gaming Hub for versions prior to 1101.2608.0.0. The vulnerability could potentiall… No fix yet Fix from $4,9002026-08-21 MEDIUM 6.9 CVE-2026-15580 vault token disclosure via unvalidated postMessage vulnerability in N-able PassPortal allows Authentication Abuse. This issue affects the PassPortal… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-77780 Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with… Patch available Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-77028 Joomla Extension - yootheme.com - Reflected XSS and open redirect via the submission redirect parameter in Zoo < 4.1.66 No fix yet Fix from $4,0002026-08-21 HIGH 8.6 CVE-2026-76613 Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-lev… No fix yet Fix from $4,9002026-08-21 HIGH 8.6 CVE-2026-76612 Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user su… No fix yet Fix from $4,9002026-08-21 MEDIUM 6.9 CVE-2026-76611 Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66. No fix yet Fix from $4,0002026-08-21 HIGH 7.0 CVE-2026-75115 Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is… No fix yet Fix from $4,9002026-08-21 MEDIUM 6.8 CVE-2026-59654 Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects diffe… No fix yet Fix from $4,0002026-08-21 CRITICAL 9.1 CVE-2026-77776 Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/p… Patch available Fix from $5,7502026-08-21 HIGH 8.6 CVE-2026-77775 Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in head… Patch available Fix from $4,9002026-08-21 HIGH 8.7 CVE-2026-77759 Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user … Patch available Fix from $4,9002026-08-21 MEDIUM 6.5 CVE-2026-59318 In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is… No fix yet Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-59279 The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default … No fix yet Fix from $4,9002026-08-21 MEDIUM 6.5 CVE-2026-19848 The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allow… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-17559 The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass gl… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-16650 The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, … No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-15150 The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured … No fix yet Fix from $4,0002026-08-21 MEDIUM 6.5 CVE-2026-77769 The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboar… Patch available Fix from $4,0002026-08-21 MEDIUM 6.5 CVE-2026-77768 The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAc… Patch available Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-77767 Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role,… Patch available Fix from $4,9002026-08-21 MEDIUM 6.5 CVE-2026-77763 The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from … Patch available Fix from $4,0002026-08-21 MEDIUM 6.3 CVE-2026-77761 A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into t… Patch available Fix from $4,0002026-08-21 MEDIUM 5.4 CVE-2026-77686 A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handl… Patch available Fix from $4,0002026-08-21 CRITICAL 9.9 CVE-2026-77683 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.1 CVE-2026-77086 SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to … No fix yet Fix from $5,7502026-08-21