Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-54682 DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-contro… Patch available Fix from $4,9002026-08-21 HIGH 7.0 CVE-2026-54134 OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and … Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-54071 BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle … Patch available Fix from $4,9002026-08-21 MEDIUM 6.2 CVE-2026-53762 VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRY… Patch available Fix from $4,0002026-08-21 HIGH 8.4 CVE-2026-77237 Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with… Freertos No fix yet Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-77236 Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap me… Freertos No fix yet Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-77235 Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-fr… Freertos No fix yet Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-77234 Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel… Freertos No fix yet Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-71862 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Patch available Fix from $4,9002026-08-21 MEDIUM 5.9 CVE-2026-71494 Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and … Patch available Fix from $4,0002026-08-21 MEDIUM 5.9 CVE-2026-71493 Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPa… Patch available Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-62677 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a se… Patch available Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-62676 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in om… Patch available Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-62675 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts a… Patch available Fix from $4,9002026-08-21 CRITICAL 9.0 CVE-2026-62674 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent chec… Patch available Fix from $5,7502026-08-21 HIGH 7.5 CVE-2026-55241 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-41451 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_art… Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-41450 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreac… Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-41449 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attack… Patch available Fix from $4,9002026-08-21 MEDIUM 6.9 CVE-2026-27875 Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may all… No fix yet Fix from $4,0002026-08-21 HIGH 7.1 CVE-2026-17252 A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-… No fix yet Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-17251 A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL-MR6400 v7. An unauthenticated remote attacker can tr… No fix yet Fix from $4,9002026-08-21 HIGH 8.5 CVE-2026-17250 A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controll… No fix yet Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-74583 In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_route: fix fastmap use-after-free on filter The route4 classifie… Fix unknown Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-74582 In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() read… Fix unknown Fix from $4,9002026-08-21 CRITICAL 9.8 CVE-2026-74581 In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_rule_suppress() drops a suppr… Fix unknown Fix from $5,7502026-08-21 HIGH 8.8 CVE-2026-74580 In the Linux kernel, the following vulnerability has been resolved: vhost: reset the vring metadata cache on vring reconfiguration vq->meta_iotlb[]… Fix unknown Fix from $4,9002026-08-21 HIGH 8.1 CVE-2026-39909 llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attacke… Patch available Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-75933 Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the … No fix yet Fix from $4,9002026-08-21 HIGH 8.6 CVE-2026-75932 Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and re… No fix yet Fix from $4,9002026-08-21