Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-53572 KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection st… Patch available Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-50538 LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server c… Patch available Fix from $4,9002026-08-21 MEDIUM 5.5 CVE-2026-45271 Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 valida… Patch available Fix from $4,0002026-08-21 MEDIUM 6.9 CVE-2026-45099 Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt … Patch available Fix from $4,0002026-08-21 MEDIUM 6.3 CVE-2026-44517 Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confi… Patch available Fix from $4,0002026-08-21 HIGH 8.0 CVE-2026-31880 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universa… Patch available Fix from $4,9002026-08-21 HIGH 8.0 CVE-2026-31803 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages… Patch available Fix from $4,9002026-08-21 HIGH 8.0 CVE-2026-30890 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro … Patch available Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-30865 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboar… Patch available Fix from $4,9002026-08-21 HIGH 8.0 CVE-2026-30826 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing … Patch available Fix from $4,9002026-08-21 CRITICAL 9.9 CVE-2026-77810 In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the co… No fix yet Fix from $5,7502026-08-21 MEDIUM 5.9 CVE-2026-76876 Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiti… Patch available Fix from $4,0002026-08-21 HIGH 8.6 CVE-2026-74252 Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable … No fix yet Fix from $4,9002026-08-21 MEDIUM 5.1 CVE-2026-67362 Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted… No fix yet Fix from $4,0002026-08-21 MEDIUM 6.9 CVE-2026-67361 Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 … No fix yet Fix from $4,0002026-08-21 MEDIUM 6.3 CVE-2026-67360 Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could… No fix yet Fix from $4,0002026-08-21 HIGH 8.7 CVE-2026-67359 Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could suppl… No fix yet Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-67358 Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a val… No fix yet Fix from $4,0002026-08-21 HIGH 7.4 CVE-2026-62960 Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transpor… Patch available Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-50290 SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(java… Patch available Fix from $4,0002026-08-21 HIGH 8.7 CVE-2026-50288 SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-30866 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This iss… Patch available Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-30819 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboar… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-27490 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected b… Patch available Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-27463 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete … Patch available Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-27462 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on mul… Patch available Fix from $4,9002026-08-21 MEDIUM 6.3 CVE-2026-77795 A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/F… No fix yet Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-63462 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/ba… Patch available Fix from $4,9002026-08-21 MEDIUM 5.5 CVE-2026-63004 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-cont… Patch available Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-55850 Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPag… Patch available Fix from $4,0002026-08-21