Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.5
CVE-2026-66151

SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which cou…

No fix yet
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.1
CVE-2026-48039

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispat…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 8.6
CVE-2026-48007

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when config…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47661

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47660

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47659

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-19113

Consul Community Edition and Consul Enterprise 1.3.0 through 2.0.2 are vulnerable to an unauthenticated denial of service in several agent HTTP API e…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.8
CVE-2026-19017

Consul Community Edition and Consul Enterprise 1.18.21 through 2.0.2 are vulnerable to a partial arbitrary file read when configured to use the Vault…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-19015

Consul Community Edition and Consul Enterprise 1.2.0 through 2.0.2 are vulnerable to an uncontrolled resource consumption issue in the Connect CA roo…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-19012

Consul Community Edition and Consul Enterprise 1.18.0 through 2.0.2 are vulnerable to an authenticated denial of service in the Enterprise-to-Communi…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.5
CVE-2026-15972

Consul Community Edition and Consul Enterprise 1.13.0 through 2.0.2 are vulnerable to an unauthenticated denial of service through unbounded connecti…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-71847

Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-70561

TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege gues…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.3
CVE-2026-48098

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute p…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.8
CVE-2026-48097

NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a co…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.3
CVE-2026-19231

A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /adm…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2025-71413

Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased …

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.1
CVE-2025-71412

Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actio…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2025-71411

Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2025-71410

Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC func…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.1
CVE-2025-71409

Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misl…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2025-63235

In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients se…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-66058

Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.9
CVE-2026-64638

WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hoste…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.9
CVE-2026-64637

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 7.7
CVE-2026-64636

An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the pan…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-47364

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing o…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.3
CVE-2026-47363

In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.4
CVE-2026-47361

In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.5
CVE-2026-44965

In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedView…

No fix yet
Fix from $1,600 2026-08-07