Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.4
CVE-2026-15554

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-10579

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-19391

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. Th…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.5
CVE-2026-16053

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exch…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-8158

The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-6505

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-6181

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.7
CVE-2026-5304

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.7
CVE-2026-5303

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.2
CVE-2026-4757

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an…

No fix yet
Fix from $1,600 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-19516

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-19425

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…

No fix yet
Fix from $2,300 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-16974

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.4
CVE-2026-8917

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a spe…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-24330

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.5
CVE-2026-19424

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66779

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-66778

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66777

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66776

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66773

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-66771

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66770

Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.9
CVE-2026-66763

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-66760

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-58247

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensi…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.8
CVE-2026-58243

SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-58238

SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input…

No fix yet
Fix from $1,600 2026-08-11