Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.3
CVE-2026-66154

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-66150

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-66149

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66148

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.4
CVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.1
CVE-2026-63177

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-63134

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-63133

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-55676

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.2
CVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administratio…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-29035

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remot…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.4
CVE-2026-18634

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-14863

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71845

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.0
CVE-2026-71475

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71474

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-71468

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-66146

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker …

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.7
CVE-2026-48813

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralizati…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18844

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These command…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-16230

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-13457

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-48809

python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of …

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-48802

python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation o…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18712

An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-18711

An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference t…

No fix yet
Fix from $4,900 2026-08-11