Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-67970

Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal.

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67969

An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.App…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67977

An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) vi…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67973

An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs.

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-48115

Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.9
CVE-2026-47746

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks durin…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.1
CVE-2026-46714

Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.2
CVE-2026-46713

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67972

An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading …

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67976

The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Den…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.4
CVE-2026-66065

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions …

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-52102

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as ro…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-51775

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-51190

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL e…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.1
CVE-2026-52521

A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the Comment…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-52520

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authen…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.8
CVE-2026-41447

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafte…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-18737

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an un…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.0
CVE-2026-18736

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.8
CVE-2026-18733

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operati…

Mitigation only
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18648

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFile…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.3
CVE-2026-18647

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidT…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18646

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component A…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18645

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the co…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.2
CVE-2026-67599

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary comma…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.4
CVE-2026-67598

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attacker…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.7
CVE-2026-62354

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit propo…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-18655

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.8
CVE-2026-18654

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow m…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18644

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the compo…

No fix yet
Fix from $1,600 2026-08-03