Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2026-77392 A weakness has been identified in SourceCodester Dynamic Input Field Generator Using HTML, CSS, and PHP 1.0. This impacts the function saveUser of th… No fix yet Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-76157 Missing authentication for a critical function in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an unau… No fix yet Fix from $4,9002026-08-21 CRITICAL 9.4 CVE-2026-76156 OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execut… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.3 CVE-2026-76155 Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.8 CVE-2026-77651 The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depen… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.8 CVE-2026-77650 The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.8 CVE-2026-77649 The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depe… No fix yet Fix from $5,7502026-08-21 HIGH 8.7 CVE-2026-16520 Improper input validation and Exposure of sensitive information through data queries vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.… No fix yet Fix from $4,9002026-08-21 CRITICAL 9.8 CVE-2026-77647 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to inc… No fix yet Fix from $5,7502026-08-20 MEDIUM 6.7 CVE-2026-77113 Path traversal in apport-unpack in Canonical Apport before 2.36.0, 2.34.2, and 2.28.4 on Linux allows an attacker to create or overwrite arbitrary fi… Patch available Fix from $4,0002026-08-20 HIGH 7.7 CVE-2026-77646 A Server-Side Request Forgery (SSRF) vulnerability has been reported in PTC Windchill PDMLink and PTC FlexPLM. The vulnerability may be exploited thr… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.2 CVE-2026-77645 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-77644 A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. No fix yet Fix from $5,7502026-08-20 HIGH 7.5 CVE-2026-77642 tor before 0.4.9.9 was prone to an out-of-bounds write when parsing a consensus or detached signature with unexpected signature digest type. Impact … No fix yet Fix from $4,9002026-08-20 HIGH 8.5 CVE-2026-72860 The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP requests to it, guarding the desti… Patch available Fix from $4,9002026-08-20 HIGH 8.6 CVE-2026-72848 SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_domain control only to leaf ur… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.4 CVE-2026-72846 Lightdash stores the webhook URL supplied with a scheduled delivery and later posts to it from sendWebhook in packages/backend/src/clients/GoogleChat… No fix yet Fix from $4,0002026-08-20 CRITICAL 9.8 CVE-2026-72843 The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, wh… No fix yet Fix from $5,7502026-08-20 HIGH 7.5 CVE-2026-72818 The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.5 CVE-2026-70105 Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a network. No fix yet Fix from $4,0002026-08-20 HIGH 7.7 CVE-2026-69855 Server-side request forgery (ssrf) in Microsoft Copilot in Azure allows an authorized attacker to disclose information over a network. No fix yet Fix from $4,9002026-08-20 CRITICAL 9.9 CVE-2026-69851 Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-69836 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. No fix yet Fix from $5,7502026-08-20 HIGH 8.6 CVE-2026-69558 Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose information over a network. No fix yet Fix from $4,9002026-08-20 CRITICAL 10.0 CVE-2026-69555 Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 HIGH 8.5 CVE-2026-69543 Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network. No fix yet Fix from $4,9002026-08-20 HIGH 8.6 CVE-2026-69519 Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a network. No fix yet Fix from $4,9002026-08-20 HIGH 8.5 CVE-2026-69419 Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. No fix yet Fix from $4,9002026-08-20 CRITICAL 9.6 CVE-2026-69400 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-68789 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p… No fix yet Fix from $5,7502026-08-20