Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-77641 tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of relay_send_command_from_edge() … No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-77639 Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-streams, each just under the per-… No fix yet Fix from $4,0002026-08-20 HIGH 8.9 CVE-2026-77638 Tor before 0.4.9.11 is prone to a race condition where in just the right circumstances a rendezvous point could man-in-the-middle (impersonate) the o… No fix yet Fix from $4,9002026-08-20 HIGH 8.8 CVE-2026-76023 Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the rendere… No fix yet Fix from $4,9002026-08-20 HIGH 8.8 CVE-2026-76022 Buffer overflow in Network in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via a cra… No fix yet Fix from $4,9002026-08-20 HIGH 8.8 CVE-2026-76021 Use after free in DOM in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted H… No fix yet Fix from $4,9002026-08-20 HIGH 7.5 CVE-2026-76020 Race condition in V8 in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HT… No fix yet Fix from $4,9002026-08-20 HIGH 8.1 CVE-2026-76019 Incorrect authorization in Workers in Google Chrome prior to 151.0.7922.173 allowed a remote attacker who had compromised the renderer process and le… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.9 CVE-2026-77587 Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last… No fix yet Fix from $4,0002026-08-20 HIGH 7.0 CVE-2026-77584 Tor before 0.4.9.10 did not reject a CONFLUX_LINK cell that arrives on a circuit which already has attached streams. A malicious client could send a … No fix yet Fix from $4,9002026-08-20 HIGH 8.8 CVE-2026-76018 Privilege elevation in Import in Google Chrome prior to 151.0.7922.173 allowed a remote attacker leveraging social engineering to potentially execute… No fix yet Fix from $4,9002026-08-20 HIGH 8.8 CVE-2026-76017 Use after free in Chromoting in Google Chrome prior to 151.0.7922.173 allowed a remote attacker to execute arbitrary code outside the sandbox via cra… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.9 CVE-2026-75484 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in mtrudel bandit allows an unauthenticated remote attacker to smuggle CR,… Patch available Fix from $4,0002026-08-20 HIGH 8.7 CVE-2026-74836 Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows an unauthenticated remote attacker to pin an unbounded nu… Patch available Fix from $4,9002026-08-20 HIGH 7.7 CVE-2026-73137 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). A tenant with HelmRelease create … No fix yet Fix from $4,9002026-08-20 HIGH 8.8 CVE-2026-73040 Dockge validates a stack name only on the write path. In backend/stack.ts the allow-list check in validate(), which requires the name to match ^[a-z0… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.1 CVE-2026-71485 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.hea… Patch available Fix from $5,7502026-08-20 MEDIUM 5.8 CVE-2026-70654 libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, applications that define unusual custom libvips sources an… Patch available Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-70651 libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, libvips built without libtiff support but with ImageMagick… Patch available Fix from $4,0002026-08-20 HIGH 8.4 CVE-2026-69242 libvips is a fast image processing library with low memory needs. Prior to version 8.18.3, a crafted many-band TIFF processed through VipsForeignLoad… Patch available Fix from $4,9002026-08-20 CRITICAL 9.9 CVE-2026-67567 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a tenant, who has the ability to create HelmRelease cu… No fix yet Fix from $5,7502026-08-20 MEDIUM 5.3 CVE-2026-67446 Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attachments into a full raster befo… Patch available Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-67445 Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/smtpd/smtpd.go session.readLin… Patch available Fix from $4,0002026-08-20 HIGH 7.2 CVE-2026-53804 OTRS Community Edition contains an authenticated OS command injection vulnerability in the PGP encryption module that allows administrators to execut… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.9 CVE-2026-19755 NoSleep 1.5.1 exposes a privileged XPC Mach service and accepts raw dictionary messages containing attacker-controlled command and NSBundlePath value… No fix yet Fix from $4,0002026-08-20 HIGH 8.8 CVE-2026-18420 Improper input validation in the Time Series Visual Builder (TSVB) plugin in OpenSearch Dashboards allows an authenticated remote user to execute arb… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.5 CVE-2026-75910 Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an au… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.8 CVE-2026-72861 The github-issue-bot templates in appwrite/templates verify the GitHub webhook signature with an inverted condition. verifyWebhook in node/github-iss… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.0 CVE-2026-9033 An unauthenticated attacker with network access to the captive portal service of an affected device can terminate active captive portal sessions, inc… No fix yet Fix from $4,0002026-08-20 CRITICAL 9.9 CVE-2026-77148 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. This impacts the function sub_44B50C of the file /cgi-bin/mbox-config?method=SET&section=ptest_… No fix yet Fix from $5,7502026-08-20