Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.6
CVE-2026-72564

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in …

No fix yet
Fix from $2,300 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-71394

GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variab…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-71393

GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a …

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-71392

GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueTy…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-71391

GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_si…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-66642

Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 throug…

No fix yet
Fix from $1,600 2026-08-10
Enterprise Linux HIGH 7.8
CVE-2026-59087

A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this …

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-66915

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the aja…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 7.5
CVE-2026-44630

Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sen…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-19404

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization …

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-66411

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may conne…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-66409

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.1
CVE-2026-66407

DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved throug…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-66405

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products.

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-66404

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affecte…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 7.5
CVE-2026-66403

DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected prod…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-21084

Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information.

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-21081

Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive informa…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-21075

Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information.

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 7.2
CVE-2026-21074

Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege.

No fix yet
Fix from $1,950 2026-08-10
Android MEDIUM 6.1
CVE-2026-21073

Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity.

No fix yet
Fix from $1,600 2026-08-10
Android HIGH 7.8
CVE-2026-21072

Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $1,950 2026-08-10
Android HIGH 7.8
CVE-2026-21071

Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-21070

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information.

No fix yet
Fix from $1,600 2026-08-10
Android HIGH 7.8
CVE-2026-21069

Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds…

No fix yet
Fix from $1,950 2026-08-10
Android HIGH 7.8
CVE-2026-21068

Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code.

No fix yet
Fix from $1,950 2026-08-10
Android HIGH 7.8
CVE-2026-21065

Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $1,950 2026-08-10
Android HIGH 7.8
CVE-2026-21067

Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $1,950 2026-08-10
Android HIGH 7.8
CVE-2026-21066

Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory.

No fix yet
Fix from $1,950 2026-08-10
Android MEDIUM 5.5
CVE-2026-21064

Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability.

No fix yet
Fix from $1,600 2026-08-10