Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-71268

OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes t…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71267

microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.8
CVE-2026-71266

tinyobjloader-c's tinyobj_parse_and_index_mtl_file (tinyobj_loader_c.h) reads each line of a .mtl material file into a fixed 4096-byte stack buffer v…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71265

Domoticz's MochadTCP::MatchLine handler for MOCHAD_RFSEC messages (hardware/MochadTCP.cpp) copies network-received data from the up-to-1028-byte m_mo…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.2
CVE-2026-71264

WLED's GET /json/cfg endpoint (registered in wled00/wled_server.cpp) calls serveJson with no settings-PIN check, unlike the /edit endpoint which expl…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71263

The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71262

IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersC…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified HIGH 7.8
CVE-2026-71261

dr_libs dr_wav.h (all versions through current master) contains an integer overflow in W64 CUE chunk metadata parsing. In drwav__metadata_process_chu…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71260

ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (esphome/components/web_server/web_…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.6
CVE-2026-71259

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py. Because binds tighter than …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.8
CVE-2026-16022

@oblique/cli 15.4.0 contains an OS command injection vulnerability in the project creation functionality. The CLI constructs shell commands through s…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-0516

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to manipulate the Host header a…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.8
CVE-2026-64582

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mma…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71256

nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.6
CVE-2026-71255

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, …

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71254

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in …

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.2
CVE-2026-18933

The wp-downloadmanager WordPress plugin, in version 1.68.11 (also affecting the 6.9.4 release line), allows an admin-privileged user (current_user_ca…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71251

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download behind only generic auth mid…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-71249

299Ko's public contact form (plugin/contact/controllers/ContactController.php, home) sets raw POST field values (name, firstname, email, message) int…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71247

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.1
CVE-2026-71245

Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with Inp…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71244

Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, ac…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71243

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd =…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.3
CVE-2026-71242

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71241

Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required dec…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-71239

DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, …

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71238

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71237

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.7
CVE-2026-71236

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPuri…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71235

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. T…

No fix yet
Fix from $1,950 2026-08-05