Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-15689 Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2025-15688 Unauthenticated SQL Injection in Capella <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-20 HIGH 8.1 CVE-2025-15637 Unauthenticated Local File Inclusion in Shuffle <= 1.8 versions. No fix yet Fix from $4,9002026-08-20 MEDIUM 5.0 CVE-2026-77067 The setWebhookResolver in packages/api/src/resolvers/webhooks/index.ts stores the caller-supplied url without any address validation, and the file im… Patch available Fix from $4,0002026-08-20 MEDIUM 5.0 CVE-2026-77066 The scanFeedsResolver in packages/api/src/resolvers/subscriptions/index.ts passes the caller-supplied url straight to axios.get(url, rssParserConfig(… Patch available Fix from $4,0002026-08-20 MEDIUM 6.5 CVE-2026-73196 A flaw was found in FreeIPA. A low-privilege authenticated user can exploit this vulnerability by submitting an oversized One-Time Password (OTP) key… Enterprise Linux 4.13.3+ Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-77026 Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Submissions view did not enforc… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.5 CVE-2026-73199 A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer dereference vulnerability by sending … No fix yet Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-73198 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit a vulnerability in the `/ipa/i18n_messages` endpoint by sending an arbitr… Enterprise Linux 4.13.3+ Fix from $4,9002026-08-20 HIGH 7.5 CVE-2026-73197 A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/m… Enterprise Linux 4.13.3+ Fix from $4,9002026-08-20 CRITICAL 9.1 CVE-2026-13097 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se… Enterprise Linux No fix yet Fix from $5,7502026-08-20 HIGH 8.1 CVE-2026-11861 A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti… Enterprise Linux 4.13.3+ Fix from $4,9002026-08-20 HIGH 7.8 CVE-2026-18917 A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-77014 A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-76610 Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing una… No fix yet Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-14952 An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional f… No fix yet Fix from $4,9002026-08-20 HIGH 8.0 CVE-2026-14951 An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. No fix yet Fix from $4,9002026-08-20 CRITICAL 9.8 CVE-2026-14950 An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th… No fix yet Fix from $5,7502026-08-20 MEDIUM 6.5 CVE-2026-14949 A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to cr… No fix yet Fix from $4,0002026-08-20 HIGH 8.8 CVE-2026-14948 A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pl… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-14947 A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extra… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-14946 A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code executio… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-76569 Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-76565 Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 No fix yet Fix from $4,0002026-08-20 HIGH 8.6 CVE-2026-76564 Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 No fix yet Fix from $4,9002026-08-20 HIGH 8.6 CVE-2026-75948 Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and … No fix yet Fix from $4,9002026-08-20 HIGH 8.6 CVE-2025-14601 An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.1 CVE-2026-71368 F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operation… No fix yet Fix from $4,0002026-08-20 HIGH 7.1 CVE-2026-14163 In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable sn… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2025-14602 The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to ac… No fix yet Fix from $4,0002026-08-20