Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-78154 A vulnerability was identified in the-momentum open-wearables up to 0.6.2. This impacts the function redeem_invitation_code of the file backend/app/a… No fix yet Fix from $4,9002026-08-24 MEDIUM 5.3 CVE-2026-78148 A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of the file ggml/src/ggml-rpc/ggm… No fix yet Fix from $4,0002026-08-24 HIGH 7.3 CVE-2026-78147 A vulnerability was found in ggml-org llama.cpp bec4772f6. The impacted element is the function deserialize_tensor of the file ggml/src/ggml-rpc/ggml… No fix yet Fix from $4,9002026-08-23 MEDIUM 6.3 CVE-2026-78144 A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown funct… No fix yet Fix from $4,0002026-08-23 HIGH 7.3 CVE-2026-78143 A vulnerability was determined in code-projects Barangay Resident Profiling Management System 1.0. Affected is an unknown function of the file reside… No fix yet Fix from $4,9002026-08-23 MEDIUM 6.3 CVE-2026-78142 A vulnerability was found in code-projects Barangay Resident Profiling Management System 1.0. This impacts an unknown function of the file /archived_… No fix yet Fix from $4,0002026-08-23 HIGH 7.4 CVE-2026-78141 A vulnerability has been found in Tenda CH22 1.0.0.1. This affects the function formexeCommand of the file /goform/exeCommand. The manipulation of th… No fix yet Fix from $4,9002026-08-23 HIGH 7.5 CVE-2026-9769 justhtml through 1.9.1 (fixed in 1.10.0) is vulnerable to uncontrolled recursion leading to denial of service. During JustHTML() construction, TreeBu… No fix yet Fix from $4,9002026-08-23 MEDIUM 6.1 CVE-2026-8630 justhtml before 1.12.0 (versions <= 1.11.0) contains a mutation cross-site scripting (mXSS) vulnerability in the serialization of raw-text elements s… No fix yet Fix from $4,0002026-08-23 CRITICAL 9.8 CVE-2026-8445 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a… No fix yet Fix from $5,7502026-08-23 CRITICAL 9.8 CVE-2026-7808 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive s… No fix yet Fix from $5,7502026-08-23 MEDIUM 6.1 CVE-2026-77088 justhtml versions 0.9.0 through 1.21.0 contain a cross-site scripting vulnerability in to_markdown() where inline code spans fail to account for blan… No fix yet Fix from $4,0002026-08-23 MEDIUM 6.1 CVE-2026-74793 justhtml before 3.11.0 contains a cross-site scripting vulnerability where the default sanitizer bypasses event handler removal in selectedcontent pr… No fix yet Fix from $4,0002026-08-23 MEDIUM 6.1 CVE-2026-6827 justhtml before 1.17.0 contains multiple security issues in sanitization, serialization, and programmatic DOM handling. When custom policies preserve… No fix yet Fix from $4,0002026-08-23 MEDIUM 6.1 CVE-2026-5751 justhtml versions 1.13.0 and earlier contain a parser-differential / mutation cross-site scripting (mXSS) vulnerability when using a custom Sanitizat… No fix yet Fix from $4,0002026-08-23 MEDIUM 6.1 CVE-2026-5389 justhtml versions before 1.13.0 contain a cross-site scripting vulnerability in the to_markdown() function when serializing attacker-controlled pre c… No fix yet Fix from $4,0002026-08-23 CRITICAL 9.8 CVE-2026-5388 justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Ma… No fix yet Fix from $5,7502026-08-23 HIGH 7.5 CVE-2026-4671 justhtml before 1.18.0 contains multiple low-severity denial-of-service issues in CSS selector handling and linkification. Applications that evaluate… No fix yet Fix from $4,9002026-08-23 CRITICAL 9.9 CVE-2026-78155 privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges No fix yet Fix from $5,7502026-08-23 MEDIUM 5.4 CVE-2026-78115 A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edit_user_… No fix yet Fix from $4,0002026-08-23 MEDIUM 6.3 CVE-2026-78112 A flaw has been found in itsourcecode Hospital Management System Project in PHP 1.0. This impacts an unknown function of the file /viewservicetype.ph… No fix yet Fix from $4,0002026-08-23 HIGH 8.5 CVE-2026-10053 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under … No fix yet Fix from $4,9002026-08-23 HIGH 7.1 CVE-2026-77115 Brave Popup Builder (brave-popup-builder) up to version 0.8.5 reflects UTM query parameters into popup form HTML without escaping them. No fix yet Fix from $4,9002026-08-23 HIGH 7.4 CVE-2026-78063 A security flaw has been discovered in Tenda CH22 1.0.0.1. The impacted element is the function formeditFileName of the file /goform/editFileName. Th… No fix yet Fix from $4,9002026-08-23 HIGH 7.3 CVE-2026-78062 A vulnerability was identified in vas3k TaxHacker up to 0.8.2. The affected element is the function envSchema.parse of the file lib/config.ts of the … No fix yet Fix from $4,9002026-08-23 MEDIUM 6.3 CVE-2026-78061 A vulnerability was determined in vas3k TaxHacker up to 0.8.2. Impacted is the function buildImapConfig of the file lib/email-sync/imap-client.ts of … Patch available Fix from $4,0002026-08-23 MEDIUM 6.3 CVE-2026-78057 A flaw has been found in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. This affects an unknown part of the comp… No fix yet Fix from $4,0002026-08-23 MEDIUM 6.3 CVE-2026-78056 A vulnerability was detected in sambitraj Student-Management-System up to 56ba287f2e9031523ccb4244cb6e3fe530e4e5d5. Affected by this issue is some un… No fix yet Fix from $4,0002026-08-23 HIGH 7.8 CVE-2026-78136 chirpmyradio CHIRP before 39178db allows eval injection via crafted CSV data. This occurs in _clean_tmode in drivers/kenwood_itm.py. Patch available Fix from $4,9002026-08-23 MEDIUM 5.3 CVE-2026-78051 A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the file /download/.metube/cookies… No fix yet Fix from $4,0002026-08-23