Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.5
CVE-2026-70630

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (li…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.5
CVE-2026-70629

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.8
CVE-2026-70628

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsu…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-70559

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-70557

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those …

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated …

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.8
CVE-2026-67687

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleContro…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-67622

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 7.6
CVE-2026-67621

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-64663

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.2
CVE-2026-63725

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-con…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.8
CVE-2026-62857

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-61632

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vul…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.8
CVE-2026-5336

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes th…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-48076

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.6
CVE-2026-47194

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-45378

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-documen…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2026-43632

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokeni…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2026-43631

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-se…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2026-43629

llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() func…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.8
CVE-2026-43628

llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.8
CVE-2026-43627

llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in …

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-3418

The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be …

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.7
CVE-2026-3415

The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain condit…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.8
CVE-2026-1289

A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vul…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2026-19111

Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19071

A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipula…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19070

A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipul…

No fix yet
Fix from $1,600 2026-08-06