Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-67358 Joomla Extension - j2commerce.com - Download quota manipulation in J2Store 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5 - An authenticated user with a val… No fix yet Fix from $4,0002026-08-21 HIGH 7.4 CVE-2026-62960 Git for Windows is the Windows port of Git. Prior to 2.55.0.windows.4, a malicious remote Git server can advertise a bundle URI that reaches transpor… Patch available Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-50290 SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, CSS value sanitization stripped `expression(` and `url(java… Patch available Fix from $4,0002026-08-21 HIGH 8.7 CVE-2026-50288 SpecifyJS is a declarative TypeScript user interface framework. Prior to version 0.2.136, when `new URL()` throws a parse error, the `assertSecureUrl… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-30866 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, unauthenticated users can access uploaded sensitive via sniffed url. This iss… Patch available Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-30819 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop has a reflected Cross-Site Scripting (XSS) vulnerability in its dashboar… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-27490 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, inline images that are accessible without being authenticated are protected b… Patch available Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-27463 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the login page contains the complete … Patch available Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-27462 Combodo iTop is a web based IT service management tool. Prior to 3.2.3, iTop returns different responses for valid/invalid usernames depending on mul… Patch available Fix from $4,9002026-08-21 MEDIUM 6.3 CVE-2026-77795 A vulnerability was identified in Dromara RuoYi-Vue-Plus up to 5.6.2. This issue affects the function FlwInstanceController/FlwDefinitionController/F… No fix yet Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-63462 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the shared OpenAPI validation error path in src/lib/error/ba… Patch available Fix from $4,9002026-08-21 MEDIUM 5.5 CVE-2026-63004 Unleash is an open-source feature management platform. Prior to 7.5.2, 7.6.5, and 8.0.2, the addon and integration subsystem passes the operator-cont… Patch available Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-55850 Element Web is a Matrix web client built using the Matrix React SDK. Prior to 1.12.22, EmbeddedPage in apps/web/src/components/structures/EmbeddedPag… Patch available Fix from $4,0002026-08-21 HIGH 8.2 CVE-2026-54682 DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, HTML exports generated with markdown formatting disabled pass attacker-contro… Patch available Fix from $4,9002026-08-21 HIGH 7.0 CVE-2026-54134 OctoPrint provides a web interface for controlling consumer 3D printers. Prior to 1.11.8 and 2.0.0rc3, OctoPrint's custom Tornado upload handler and … Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-54071 BabelDOC is a document translation tool. Prior to 0.6.3, BabelDOC's vendored PDF parser in babeldoc/pdfminer/cmapdb.py deserializes untrusted pickle … Patch available Fix from $4,9002026-08-21 MEDIUM 6.2 CVE-2026-53762 VeraCrypt provides disk encryption with strong security based on TrueCrypt. Prior to 1.26.29, non-default builds created with WOLFCRYPT=1 and WOLFCRY… Patch available Fix from $4,0002026-08-21 MEDIUM 6.5 CVE-2026-77237 Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports with… No fix yet Fix from $4,0002026-08-21 HIGH 7.3 CVE-2026-77236 Missing minimum size validation in secure context allocation in FreeRTOS-Kernel before 11.3.1 might allow local users to corrupt secure-world heap me… No fix yet Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-77235 Missing privilege verification in the secure context cleanup handler in FreeRTOS-Kernel before 11.3.1 might allow local users to cause a use-after-fr… No fix yet Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-77234 Improper input validation in FreeRTOS-Kernel before 11.3.1 might allow an unprivileged task on MPU-enabled ports to execute code in privileged kernel… No fix yet Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-71862 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Patch available Fix from $4,9002026-08-21 MEDIUM 5.9 CVE-2026-71494 Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, internal/hcl/remote_variables_loader.go and … Patch available Fix from $4,0002026-08-21 MEDIUM 5.9 CVE-2026-71493 Infracost provides cloud cost intelligence for engineers, AI coding agents, and CI/CD. Prior to 0.10.45, the readFile, pathExists, isDir, and matchPa… Patch available Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-62677 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, an authenticated user can upload a se… Patch available Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-62676 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, the shared shell-command parser in om… Patch available Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-62675 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, multipart POST /v1/sessions accepts a… Patch available Fix from $4,9002026-08-21 CRITICAL 9.0 CVE-2026-62674 Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent chec… Patch available Fix from $5,7502026-08-21 HIGH 7.5 CVE-2026-55241 Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with … Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-41451 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the user substitution logic within parse_art… Patch available Fix from $4,9002026-08-21