Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.2
CVE-2026-67333

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the …

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-67332

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens fo…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67331

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authentic…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.9
CVE-2026-67330

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authoriza…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 7.1
CVE-2026-67329

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscri…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.1
CVE-2026-67328

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign …

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67327

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.0
CVE-2026-67326

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary sect…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.8
CVE-2026-67325

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. A…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67324

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default …

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 8.4
CVE-2026-67323

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing comm…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67322

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.9
CVE-2026-67321

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with …

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67319

axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67318

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent w…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67317

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length ca…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67316

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.9
CVE-2026-67315

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing reques…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67314

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpe…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67313

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segm…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67312

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON()…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.8
CVE-2026-67311

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects …

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-67310

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of …

No fix yet
Fix from $1,600 2026-08-01
Unclassified CRITICAL 9.3
CVE-2026-67308

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.4
CVE-2026-67305

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONT…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67297

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67296

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length b…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.1
CVE-2025-71403

better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. At…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-6453

The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient inpu…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-18435

The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Blo…

No fix yet
Fix from $1,600 2026-08-01