Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-54494 Koel is a free, open-source music streaming solution. Prior to 9.7.1, App\Helpers\Network::isPublicHost() uses filter_var() with FILTER_FLAG_NO_PRIV_… Patch available Fix from $4,0002026-08-19 HIGH 7.7 CVE-2026-54493 Koel is a free, open-source music streaming solution. Prior to 9.7.0, the Subsonic-compatible createInternetRadioStation.view and updateInternetRadio… Patch available Fix from $4,9002026-08-19 HIGH 7.1 CVE-2026-54491 Koel is a free, open-source music streaming solution. Prior to 9.7.1, outbound podcast and radio fetch paths perform a point-in-time App\Helpers\Netw… Patch available Fix from $4,9002026-08-19 HIGH 7.7 CVE-2026-53549 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /host/db/proxy… Patch available Fix from $4,9002026-08-19 CRITICAL 9.6 CVE-2026-53548 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:… Patch available Fix from $5,7502026-08-19 HIGH 8.8 CVE-2026-53547 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the POST /database/expo… Patch available Fix from $4,9002026-08-19 CRITICAL 9.6 CVE-2026-53546 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket … Patch available Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-53545 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/… Patch available Fix from $5,7502026-08-19 HIGH 8.8 CVE-2026-53542 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the archive creation en… Patch available Fix from $4,9002026-08-19 MEDIUM 6.0 CVE-2026-4937 IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H2 could allow a local attacker with admi… Power System S1122 \(9824 22a\) Firmware No fix yet Fix from $4,0002026-08-19 MEDIUM 6.2 CVE-2026-4936 IBM PowerVM Hypervisor Platform KeyStore (PKS) and virtual TPM FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H… Power System S1122 \(9824 22a\) Firmware No fix yet Fix from $4,0002026-08-19 MEDIUM 6.8 CVE-2026-18849 IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker with authenticated administrat… No fix yet Fix from $4,0002026-08-19 HIGH 8.1 CVE-2026-18544 IBM Portieris 0.5.0 through 0.14.2 could allow a remote authenticated attacker to bypass image policy enforcement due to improper authorization of po… No fix yet Fix from $4,9002026-08-19 HIGH 8.1 CVE-2026-17015 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service and obtain sensitive information due to an out-… I No fix yet Fix from $4,9002026-08-19 MEDIUM 5.5 CVE-2026-14978 HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sensitive files to be included in… No fix yet Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-14514 IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sending a specially crafted request… No fix yet Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-12634 The NVS backend of the Zephyr settings subsystem (subsys/settings/src/settings_nvs.c) reads stored setting-name entries into fixed 74-byte stack buff… Patch available Fix from $4,0002026-08-19 HIGH 8.1 CVE-2026-12633 The IPv6 neighbor-discovery code in subsys/net/ip/ipv6_nbr.c processes the 6LoWPAN Context Option (6CO, RFC 6775) carried inside ICMPv6 Router Advert… Patch available Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-12522 The HL7800 cellular modem driver's +CGCONTRDP: response handler on_cmd_atcmdinfo_ipaddr() in drivers/modem/vendor_standalone/hl7800.c parses the PDP-… Patch available Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-76574 A flaw has been found in code-projects Hospital Information System 1.0. The impacted element is the function User::login of the file includes/users/U… No fix yet Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-75593 BuildKit is a toolkit for converting source code to build artifacts in an efficient, expressive and repeatable manner. Prior to 0.31.2, a custom clie… No fix yet Fix from $4,9002026-08-19 MEDIUM 6.9 CVE-2026-75112 A security issue exists within OTTO® Fleet Manager. The vulnerability stems from the use of an insufficient work factor in the bcrypt password hashin… No fix yet Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-68901 Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/attachments/:attachmentId/export… Patch available Fix from $4,0002026-08-19 HIGH 7.6 CVE-2026-68900 Wekan is open source kanban built with Meteor. From 8.72 until 10.23, addBoardHTMLToZip() in client/lib/exportHTML.js read a card title and body thro… Patch available Fix from $4,9002026-08-19 HIGH 8.7 CVE-2026-68899 Wekan is open source kanban built with Meteor. Prior to 9.90, isFileValid() in models/fileValidation.js used the Unix file command for content-based … Patch available Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-68561 Wekan is open source kanban built with Meteor. Prior to 9.89, the second Boards.allow({ update }) rule in server/permissions/boards.js called canUpda… Patch available Fix from $4,9002026-08-19 HIGH 7.7 CVE-2026-68560 Wekan is open source kanban built with Meteor. Prior to 9.75, models/fileValidation.js interpolated the uploaded fileObj.path into the administrator-… Patch available Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-68559 Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in models/exportExcel.js called the a… Patch available Fix from $4,0002026-08-19 HIGH 8.5 CVE-2026-68558 Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models/integrations.js checked… Patch available Fix from $4,9002026-08-19 MEDIUM 6.1 CVE-2026-67189 pfSense Plus before 26.07 and pfSense CE through 2.8.1 contain a stored cross-site scripting vulnerability in the Traffic Graphs top-talkers feature,… No fix yet Fix from $4,0002026-08-19