Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-73254 Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can create a file with an HTML payload in its name can trigger… Patch available Fix from $4,0002026-08-20 CRITICAL 9.1 CVE-2026-73253 Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildcard certificate for a parent d… Patch available Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-73251 Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server to a Mongoose client configure… Patch available Fix from $5,7502026-08-20 MEDIUM 6.3 CVE-2026-72844 The Lean 4 kernel does not verify that the structure named in a projection expression matches the type of the value being projected, and environment:… Patch available Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-63495 Libevent is an event notification library. From 2.2.0-alpha-dev until 2.2.2-alpha, the libevent WebSocket server in ws.c accumulates fragmented frame… Patch available Fix from $4,9002026-08-20 HIGH 8.4 CVE-2026-63388 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a heap out-of-bounds write in bufferevent_sock.c when buffer… Patch available Fix from $4,9002026-08-20 HIGH 7.0 CVE-2026-63387 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an off-by-one stack buffer overflow in evdns.c when dnsname_… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.2 CVE-2026-63385 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in http.c. evhttp_decode_uri_int… Patch available Fix from $5,7502026-08-20 HIGH 8.7 CVE-2026-63384 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion in event_tagging.c when evta… Patch available Fix from $4,9002026-08-20 HIGH 8.7 CVE-2026-63383 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuffer region in event_tagging.c … Patch available Fix from $4,9002026-08-20 CRITICAL 9.2 CVE-2026-63382 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsistently handles duplicate Tra… Patch available Fix from $5,7502026-08-20 MEDIUM 5.8 CVE-2026-63381 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c when evbuffer_add_buffer_refere… Patch available Fix from $4,0002026-08-20 MEDIUM 5.7 CVE-2026-63380 Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c when evws_new_session enters … Patch available Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-63379 Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in http.c through evhttp_read_tr… Patch available Fix from $4,0002026-08-20 HIGH 7.1 CVE-2026-54623 django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0.8, the move_plugin endpoint … Patch available Fix from $4,9002026-08-20 HIGH 7.6 CVE-2026-53425 Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML r… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.1 CVE-2026-53424 Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.4 CVE-2026-2334 An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-side file validation in the "I… No fix yet Fix from $5,7502026-08-20 HIGH 8.1 CVE-2026-77176 A flaw was found in Kata Containers. In configurations utilizing genpolicy for Confidential Containers guest protection, a malicious host operator ca… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.3 CVE-2026-77025 A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentpending.php. … No fix yet Fix from $4,0002026-08-20 CRITICAL 9.9 CVE-2026-77022 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function sub_44B438 of the file /cgi-bin/mbox-config?me… No fix yet Fix from $5,7502026-08-20 HIGH 7.3 CVE-2026-77020 A vulnerability was identified in CodeAstro Apartment Visitor Management System 1.0. Affected by this vulnerability is an unknown functionality of th… No fix yet Fix from $4,9002026-08-20 HIGH 7.3 CVE-2026-77019 A vulnerability was determined in CodeAstro Apartment Visitor Management System 1.0. Affected is an unknown function of the file /apartment-visitor/f… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.0 CVE-2026-71492 Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry.set() in src/banks/registrie… Patch available Fix from $4,0002026-08-20 CRITICAL 9.3 CVE-2026-71428 The unstructured library provides open-source components for ingesting and pre-processing images and text documents, such as PDFs, HTML, Word docs, a… Patch available Fix from $5,7502026-08-20 HIGH 7.5 CVE-2026-69183 Monkeytype is a minimalistic and customizable typing test. In 26.26.0 and earlier, the backend rate-limit key generator in backend/src/middlewares/ra… No fix yet Fix from $4,9002026-08-20 HIGH 8.2 CVE-2026-65842 Plate is a rich-text editor with AI and shadcn/ui. Prior to 53.3.2, @platejs/docx-io fetches remote image URLs while converting attacker-controlled H… Patch available Fix from $4,9002026-08-20 MEDIUM 6.9 CVE-2026-63481 Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier, the redirect handling in pac… Patch available Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-61704 Link Preview JS extracts web links information. Prior to 4.0.4, the resolveDNSHost mitigation in index.ts validates one resolved IP address but fetch… Patch available Fix from $4,9002026-08-20 MEDIUM 6.8 CVE-2026-61625 VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.146.0, vmrestore does not val… Patch available Fix from $4,0002026-08-20