Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-76996 A security flaw has been discovered in SourceCodester Simple Online Food Ordering System 1.0. Impacted is an unknown function of the file /fos/admin/… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.0 CVE-2026-76993 A vulnerability was determined in GreyDGL PentestGPT up to 1.0.0. This vulnerability affects unknown code of the component Web-Page Crawling. Executi… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-76991 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /viewappointmentapproved.php. Perf… No fix yet Fix from $4,0002026-08-20 HIGH 8.5 CVE-2026-73220 CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the audio-task annotation guide ren… Patch available Fix from $4,9002026-08-20 HIGH 7.5 CVE-2026-63490 Handlebars.java provides logic-less and semantic Mustache templates with Java. Prior to 4.5.3, com.github.jknack.handlebars.springmvc.SpringTemplateL… Patch available Fix from $4,9002026-08-20 HIGH 7.8 CVE-2026-61898 The Ubuntu-specific language helper scripts (save-to-pam-env, update-langlist) shipped with accountsservice before 23.13.9-8ubuntu7 treat the user-co… No fix yet Fix from $4,9002026-08-20 HIGH 7.8 CVE-2026-61897 An Ubuntu-specific patch to AccountsService before 23.13.9-8ubuntu7 only partially drops privileges before launching language helper scripts. It chan… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.9 CVE-2026-55558 aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.2, SMTPProtocol.start_tls in src/aiosmtplib/protocol.py consumes the ser… Patch available Fix from $4,0002026-08-20 HIGH 8.2 CVE-2026-49825 lxml is a library for processing XML and HTML in the Python language. Prior to 6.1.1, link attributes in ``lxml.html.defs.link_attrs`` were missing `… Patch available Fix from $4,9002026-08-20 MEDIUM 6.6 CVE-2026-44725 EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT, and connected vehicles. Prior to versions 5.8.11, 5.9.3, 5.10.4, 6.0.3, 6.1.2, and 6.2… Patch available Fix from $4,0002026-08-20 HIGH 8.8 CVE-2026-16932 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary commands due to improper validation of the ODMDIR env… No fix yet Fix from $4,9002026-08-20 HIGH 7.5 CVE-2026-16928 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a heap-based buffer overflow. No fix yet Fix from $4,9002026-08-20 HIGH 7.3 CVE-2026-16927 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain root privileges due to a time-of-check to time-of-use (TOCTOU) rac… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.1 CVE-2026-16926 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to overwrite arbitrary files due to improper neutralization of special el… No fix yet Fix from $5,7502026-08-20 HIGH 7.1 CVE-2026-16925 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to achieve privilege escalation due to improper authorization. No fix yet Fix from $4,9002026-08-20 HIGH 7.5 CVE-2026-16924 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an improper calculation of a memory o… No fix yet Fix from $4,9002026-08-20 HIGH 7.0 CVE-2026-16923 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to improper privilege management. No fix yet Fix from $4,9002026-08-20 HIGH 7.0 CVE-2026-16922 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a time-of-check to time-of-use (TOCTOU) r… No fix yet Fix from $4,9002026-08-20 HIGH 7.3 CVE-2026-76990 A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete… No fix yet Fix from $4,9002026-08-20 HIGH 7.8 CVE-2026-76833 @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a cust… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-76635 baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-con… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.5 CVE-2026-76634 WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to acc… No fix yet Fix from $4,0002026-08-20 HIGH 8.1 CVE-2026-76633 WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their acco… No fix yet Fix from $4,9002026-08-20 HIGH 8.4 CVE-2026-70383 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 … Patch available Fix from $4,9002026-08-20 MEDIUM 5.1 CVE-2026-64970 ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript pay… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-64969 ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a stud… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.1 CVE-2026-64968 ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary i… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-64967 A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the i… No fix yet Fix from $4,0002026-08-20 HIGH 8.7 CVE-2026-64966 ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-64965 ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enro… No fix yet Fix from $4,0002026-08-20