Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.5 CVE-2026-69419 Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a network. No fix yet Fix from $4,9002026-08-20 CRITICAL 9.6 CVE-2026-69400 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… Azure Logic Apps No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-68789 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p… Azure Sql Database No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-68782 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p… Azure Sql Database No fix yet Fix from $5,7502026-08-20 MEDIUM 6.5 CVE-2026-67448 Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin middleware checks the raw Reques… Patch available Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-67447 Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go readData() function calls bufio.… Patch available Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-66800 Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a network. Azure Data Factory No fix yet Fix from $4,9002026-08-20 CRITICAL 9.1 CVE-2026-66309 Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. Azure Sql Database No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-65816 Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. Azure Web Apps No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-65801 Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. Exchange Online No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-65770 Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthori… Azure Managed Instance For Apache Cassandra No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-63509 Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-62834 Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. Azure Data Factory No fix yet Fix from $5,7502026-08-20 MEDIUM 6.8 CVE-2026-55894 Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c sh_disassemble() function computes an idx value… Patch available Fix from $4,0002026-08-20 HIGH 7.3 CVE-2026-55893 Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Capstone's arch/SH/SHDisassembler.c SH floating-point decoders such as opFADD, opFM… Patch available Fix from $4,9002026-08-20 CRITICAL 9.4 CVE-2026-55769 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened … Patch available Fix from $5,7502026-08-20 HIGH 8.5 CVE-2026-55765 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG embedde… Patch available Fix from $4,9002026-08-20 MEDIUM 5.4 CVE-2026-55491 BigBlueButton is an open-source virtual classroom. Prior to 3.0.29, BigBlueButton failed to escape meetingName in record-and-playback/screenshare/pla… Patch available Fix from $4,0002026-08-20 MEDIUM 5.5 CVE-2026-55015 Uncontrolled search path element in Windows Remote Help allows an authorized attacker to deny service locally. No fix yet Fix from $4,0002026-08-20 HIGH 7.1 CVE-2026-55013 Uncontrolled search path element in Windows Remote Help Defense allows an authorized attacker to perform spoofing locally. No fix yet Fix from $4,9002026-08-20 MEDIUM 6.5 CVE-2026-54509 TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src/routes/journey.ts returns th… Patch available Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-54508 TREK is a collaborative travel planner. Prior to 3.1.0, TREK validates only the initial URL before native redirect following in importGoogleList() an… Patch available Fix from $4,0002026-08-20 MEDIUM 5.5 CVE-2026-54389 Ghidra before 12.1.3 contains an uncontrolled resource consumption vulnerability in the PDB parser that allows attackers to terminate the Ghidra proc… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-50192 Kerberos Agent is an open source video (surveillance) management agent. Prior to version 3.6.26, the Kerberos Hub upload path sends the agent's Hub c… Patch available Fix from $4,0002026-08-20 HIGH 7.3 CVE-2026-49436 LinkAce is a self-hosted archive to collect website links. Prior to version 2.5.7, the Bulk Link API endpoint (`POST /api/v2/bulk/links`) accepts URL… Patch available Fix from $4,9002026-08-20 MEDIUM 5.9 CVE-2026-49244 SFTPGo is an open source, event-driven file transfer solution. From 2.2.0 until 2.7.3, the public web-client partial ZIP download endpoint for a brow… Patch available Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-49217 Mailu is a mail server as a set of Docker images. Prior to version 2024.06.52, a missing authorization check in the Mailu admin REST API allows any u… No fix yet Fix from $4,9002026-08-20 HIGH 8.5 CVE-2026-46682 BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to inject SQL through the meetingI… Patch available Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-46355 BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton exposed /bigbluebutton/api/handleJoinExistingUser through bigbluebu… Patch available Fix from $4,9002026-08-20 HIGH 7.8 CVE-2026-19783 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause kernel memory corruption due to insufficient validation. A crafte… Vios Fix available Fix from $4,9002026-08-20