Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-68508 Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects sele… Patch available Fix from $4,9002026-08-21 HIGH 8.1 CVE-2026-64679 Atlantis is a self-hosted golang application that listens for Terraform pull request events via webhooks. From 0.19.8 until 0.45.0, Atlantis does not… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-63421 Keystone is a content management system for Node.js. Prior to 6.5.3, the findMany resolver in packages/core/src/lib/core/queries/resolvers.ts compare… Patch available Fix from $4,9002026-08-21 HIGH 8.2 CVE-2026-63135 YOURLS is a self-hosted, customizable URL shortener written in PHP. From 1.5.1 until 1.10.4, YOURLS stores the HTTP Referer header through yourls_get… Patch available Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-62316 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, ufo/client/mcp/http_servers/linux_mcp_se… Patch available Fix from $4,9002026-08-21 CRITICAL 9.9 CVE-2026-62283 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 thro… Patch available Fix from $5,7502026-08-21 HIGH 8.2 CVE-2026-61824 Defuddle cleans up HTML pages. Prior to 0.19.1, site extractors interpolate page-derived image alt and src values, og:image values, and video descrip… Patch available Fix from $4,9002026-08-21 CRITICAL 10.0 CVE-2026-61539 Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Ll… Patch available Fix from $5,7502026-08-21 CRITICAL 9.2 CVE-2026-59989 Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the… Patch available Fix from $5,7502026-08-21 MEDIUM 5.1 CVE-2026-55185 Miniflux 2 is an open source feed reader. Prior to 2.3.1, IsRelativePath in internal/urllib/url.go accepts redirect targets containing backslashes be… Patch available Fix from $4,0002026-08-21 MEDIUM 6.5 CVE-2026-55168 Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-controlled backup archive and c… Patch available Fix from $4,0002026-08-21 HIGH 7.7 CVE-2026-54457 TensorZero is an open-source LLMOps platform that unifies an LLM gateway, observability, evaluation, optimization, and experimentation. Prior to 2026… Patch available Fix from $4,9002026-08-21 MEDIUM 6.3 CVE-2026-53656 FiftyOne is an open-source platform for refining high-quality datasets and visual AI models. Prior to 1.17.0, the FiftyOne App/API server in fiftyone… Patch available Fix from $4,0002026-08-21 MEDIUM 5.9 CVE-2026-53572 KEDA is a Kubernetes-based Event Driven Autoscaling component. Prior to 2.20.0, pkg/scalers/postgresql_scaler.go constructs libpq-style connection st… Patch available Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-50538 LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server c… Patch available Fix from $4,9002026-08-21 MEDIUM 5.5 CVE-2026-45271 Picotls is a TLS protocol library that allows users select different crypto backends based on their use case. Picotls implements its own ASN.1 valida… Patch available Fix from $4,0002026-08-21 MEDIUM 6.9 CVE-2026-45099 Terragrunt is a flexible orchestration tool that allows Infrastructure as Code written in OpenTofu or Terraform to scale. Prior to 1.0.4, Terragrunt … Patch available Fix from $4,0002026-08-21 MEDIUM 6.3 CVE-2026-44517 Buildah is a tool that facilitates building OCI images. From 1.38.1 until 1.43.2 and 1.44.0, TempDirForURL in define/types.go does not securely confi… Patch available Fix from $4,0002026-08-21 HIGH 8.0 CVE-2026-31880 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the universa… Patch available Fix from $4,9002026-08-21 HIGH 8.0 CVE-2026-31803 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in pages… Patch available Fix from $4,9002026-08-21 HIGH 8.0 CVE-2026-30890 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the synchro … Patch available Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-30865 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the dashboar… Patch available Fix from $4,9002026-08-21 HIGH 8.0 CVE-2026-30826 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there is a Reflected Cross-Site Scripting (XSS) vulnerability in the testing … Patch available Fix from $4,9002026-08-21 CRITICAL 9.9 CVE-2026-77810 In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the co… No fix yet Fix from $5,7502026-08-21 MEDIUM 5.9 CVE-2026-76876 Craftplan before 0.5.1 contains a broken access control vulnerability that allows unauthenticated attackers to read sensitive credentials by exploiti… Patch available Fix from $4,0002026-08-21 HIGH 8.6 CVE-2026-74252 Joomla Extension - j2commerce.com - Stored XSS in Guest checkout in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - J2Commerce 4.1.5 is vulnerable … No fix yet Fix from $4,9002026-08-21 MEDIUM 5.1 CVE-2026-67362 Joomla Extension - j2commerce.com - Open redirect in cart controller in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - Four task handlers accepted… No fix yet Fix from $4,0002026-08-21 MEDIUM 6.9 CVE-2026-67361 Joomla Extension - j2commerce.com - Unauthenticated file upload with missing directory protection in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 … No fix yet Fix from $4,0002026-08-21 MEDIUM 6.3 CVE-2026-67360 Joomla Extension - j2commerce.com - Cross-customer order replication in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user could… No fix yet Fix from $4,0002026-08-21 HIGH 8.7 CVE-2026-67359 Joomla Extension - j2commerce.com - Order content disclosure J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An unauthenticated visitor could suppl… No fix yet Fix from $4,9002026-08-21