Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Mt8910 Firmware MEDIUM 6.0
CVE-2026-20475

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious ac…

No fix yet
Fix from $1,600 2026-08-03
Mt6991 Firmware MEDIUM 6.0
CVE-2026-20474

In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious acto…

No fix yet
Fix from $1,600 2026-08-03
Mt6991 Firmware MEDIUM 6.0
CVE-2026-20473

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.2
CVE-2026-20470

In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.0
CVE-2026-20469

In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a m…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.0
CVE-2026-20468

In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious acto…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.0
CVE-2026-20467

In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-20466

In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attac…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.1
CVE-2026-20465

In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-20464

In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.1
CVE-2026-65875

BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malici…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-3245

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-68582

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.5
CVE-2026-68580

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL …

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-68578

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently …

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-67357

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluste…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 8.8
CVE-2026-67356

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.9
CVE-2025-71401

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An …

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.1
CVE-2025-71400

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 6.4
CVE-2026-12231

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v…

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing…

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak HIGH 7.2
CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…

No fix yet
Fix from $1,950 2026-08-02
Build Of Keycloak MEDIUM 5.4
CVE-2026-18570

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-16292

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.5
CVE-2026-16540

The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-16285

The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a…

No fix yet
Fix from $1,950 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-16256

The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us…

No fix yet
Fix from $2,300 2026-08-02
Unclassified HIGH 7.5
CVE-2026-16261

The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it iss…

No fix yet
Fix from $1,950 2026-08-02