Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-41450 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _command_collector function where foreac… Patch available Fix from $4,9002026-08-21 HIGH 7.8 CVE-2026-41449 UAC (Unix-like Artifacts Collector) versions prior to 3.3.0 contain a command injection vulnerability in the _run_command function that allows attack… Patch available Fix from $4,9002026-08-21 MEDIUM 6.9 CVE-2026-27875 Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may all… No fix yet Fix from $4,0002026-08-21 HIGH 7.1 CVE-2026-17252 A stack-based out-of-bounds write vulnerability exists in the login request handling functionality of the administrative web interface of TP-Link TL-… No fix yet Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-17251 A NULL pointer dereference vulnerability exists in the HTTP request parsing functionality of  TL-MR6400 v7. An unauthenticated remote attacker can tr… No fix yet Fix from $4,9002026-08-21 HIGH 8.5 CVE-2026-17250 A stack-based buffer overflow vulnerability exists in the firmware update functionality of TL-MR6400 v7 due to unsafe processing of attacker-controll… No fix yet Fix from $4,9002026-08-21 HIGH 8.1 CVE-2026-39909 llama.cpp before b8585 contains a use-after-free vulnerability in the RPC server's GRAPH_RECOMPUTE handler that allows unauthenticated remote attacke… Patch available Fix from $4,9002026-08-21 HIGH 7.3 CVE-2026-75933 Jet Admin allows an authenticated attacker to inject JavaScript via the sign-in page's scripts and styles option. Injected script is executed in the … No fix yet Fix from $4,9002026-08-21 HIGH 8.6 CVE-2026-75932 Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authentication configuration, and re… No fix yet Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-75928 The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in requests to users, allowing a re… No fix yet Fix from $4,0002026-08-21 CRITICAL 10.0 CVE-2026-69502 Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-21 HIGH 7.5 CVE-2026-54789 mod_auth_openidc is an OpenID Certified authentication and authorization module for the Apache 2.x HTTP server that implements the OpenID Connect Rel… Patch available Fix from $4,9002026-08-21 HIGH 7.1 CVE-2026-49114 In ONNX before 1.21.0, the 'save_external_data' function builds the external-data file path from the model's external_data location field and opens i… No fix yet Fix from $4,9002026-08-21 HIGH 8.5 CVE-2026-22681 OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege attackers to access internal net… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-77815 to_abs_path in scripts/iib/tool.py normalised the requested path with os.path.normpath, which collapses dot segments but does not resolve symbolic li… Patch available Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-77814 is_path_trusted in scripts/iib/api.py compares the requested path against each allowed parent directory with path.startswith(parent_path), without ap… Patch available Fix from $4,9002026-08-21 CRITICAL 9.4 CVE-2026-77812 DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.6 CVE-2026-77087 Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebindi… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-63343 Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to a… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-63125 Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC i… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-62941 Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction ch… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-62940 Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied … No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-62867 Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in stora… No fix yet Fix from $5,7502026-08-21 HIGH 7.7 CVE-2026-55622 Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for instance copying where an att… No fix yet Fix from $4,9002026-08-21 HIGH 7.7 CVE-2026-55621 Incus is a system container and virtual machine manager. Prior to version 7.2.0, missing authorization checks exist for custom volume copying where a… No fix yet Fix from $4,9002026-08-21 MEDIUM 6.5 CVE-2026-50278 iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 have a `CIccEmbedIO::Read8()` … Patch available Fix from $4,0002026-08-21 CRITICAL 9.9 CVE-2026-48769 Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious … No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-48755 Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm le… No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-48753 Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and … No fix yet Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-48752 Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or … No fix yet Fix from $5,7502026-08-21