Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-18618

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service …

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18617

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.5
CVE-2026-18611

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such …

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2026-18608

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privile…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the …

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.0
CVE-2026-15581

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and dire…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.1
CVE-2026-15467

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by …

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-14450

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP head…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.8
CVE-2026-13717

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard…

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72882

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for …

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.8
CVE-2026-69118

Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.2
CVE-2026-14886

Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2025-15683

TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attack…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2025-15682

TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can…

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.2
CVE-2025-15681

TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13294

An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2025-13293

A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 7.5
CVE-2026-71962

Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that …

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.6
CVE-2026-6791

When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use…

No fix yet
Fix from $1,600 2026-08-10
Enterprise Linux HIGH 7.8
CVE-2026-59091

A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by trick…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-12339

A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequ…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

No fix yet
Fix from $1,600 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-72899

Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72737

Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs …

No fix yet
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-70622

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read …

No fix yet
Fix from $1,600 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48159

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicio…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-16626

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.6
CVE-2026-10754

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass s…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-71577

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.5
CVE-2026-71576

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status t…

No fix yet
Fix from $1,950 2026-08-10