Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-16835 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulner… Power System E1080 \(9080 Hex\) Firmware No fix yet Fix from $5,7502026-08-19 HIGH 8.4 CVE-2026-16832 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulner… Power System E1080 \(9080 Hex\) Firmware No fix yet Fix from $4,9002026-08-19 HIGH 7.6 CVE-2026-16828 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulner… Power System E1080 \(9080 Hex\) Firmware No fix yet Fix from $4,9002026-08-19 CRITICAL 9.6 CVE-2026-16687 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulne… Power System E1180 \(9080 Heu\) Firmware No fix yet Fix from $5,7502026-08-19 HIGH 8.8 CVE-2026-75149 marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary comman… Patch available Fix from $4,9002026-08-19 MEDIUM 6.3 CVE-2026-73829 Time-of-check Time-of-use (TOCTOU) Race Condition in ZenHive mpp allows an unauthenticated remote client to redeem one confirmed on-chain payment for… Patch available Fix from $4,0002026-08-19 HIGH 8.3 CVE-2026-73541 Allocation of Resources Without Limits or Throttling in ZenHive mpp allows an unauthenticated remote client to drain the fee-payer wallet through con… Patch available Fix from $4,9002026-08-19 HIGH 8.2 CVE-2026-73136 Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated third party to obtain paid resources by replaying a transfer settled… Patch available Fix from $4,9002026-08-19 CRITICAL 9.3 CVE-2026-72717 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or bac… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-72716 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or bac… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71871 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or bac… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71869 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or bac… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71868 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a ${...} expression or bac… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71867 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a single quote in a schema… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71866 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. From version 8.19.0 until 8.21.0, a double … Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71865 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a query … Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-71864 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, a double quote in a header… Patch available Fix from $5,7502026-08-19 MEDIUM 5.4 CVE-2026-69159 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_plane_rle and planar_decompress_plane_rle_only in… Patch available Fix from $4,0002026-08-19 HIGH 8.7 CVE-2026-67581 Authentication Bypass by Capture-replay in ZenHive mpp allows an unauthenticated remote client to obtain paid resources by resubmitting one settled o… Patch available Fix from $4,9002026-08-19 CRITICAL 9.3 CVE-2026-66794 A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker,… No fix yet Fix from $5,7502026-08-19 HIGH 7.1 CVE-2026-63652 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c … Patch available Fix from $4,9002026-08-19 HIGH 7.7 CVE-2026-63633 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_Ensu… Patch available Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-63117 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlig… Patch available Fix from $4,0002026-08-19 CRITICAL 9.3 CVE-2026-62682 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in s… Patch available Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-62681 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in a… Patch available Fix from $5,7502026-08-19 HIGH 7.1 CVE-2026-62680 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and … Patch available Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-61518 ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods i… No fix yet Fix from $4,9002026-08-19 MEDIUM 6.1 CVE-2026-55648 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calcu… Patch available Fix from $4,0002026-08-19 MEDIUM 5.4 CVE-2026-55564 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whe… Patch available Fix from $4,0002026-08-19 HIGH 8.7 CVE-2026-55194 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c en… Patch available Fix from $4,9002026-08-19