Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-51291

sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheInsert function of the JSON cache management module.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-51290

SQLite 3.41 has a use-after-free vulnerability in the shared cache lock management logic of the btree module. The program frees a BtLock structure wi…

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.4
CVE-2026-11885

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.2
CVE-2026-67596

CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all st…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.8
CVE-2026-58222

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When…

Mitigation only
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-58216

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.5
CVE-2026-57862

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin…

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-4978

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL …

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-23981

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboar…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.1
CVE-2026-15658

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of o…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-15657

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the respons…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.1
CVE-2026-67348

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anot…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-16308

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.4.SP2, and 3.33.1 through 3.33.2.SP2 Quarkus REST could allow a remote attacker to cause a denial…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.8
CVE-2026-67351

Serendipity before 2.6.1 contains an authentication context confusion vulnerability where password validation and session loading operate independent…

Mitigation only
Fix from $1,950 2026-07-30
Unclassified HIGH 8.3
CVE-2026-5219

Cross-Site request forgery (CSRF) vulnerability in Softtr Information Technology Trade Ltd. Co. E-Commerce Pack allows Cross Site Request Forgery. T…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-58218

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY name cache before being rejec…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.1
CVE-2026-56428

The SSH service on BSH ELP (Electronic Platform) modules contains a platform-specific vulnerability due to an improperly secured default configuratio…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 8.2
CVE-2026-12722

Missing authentication for critical function vulnerability in FTC Software IT Services FTC E-Commerce Management Panel allows Authentication Bypass. …

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-59309

VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may …

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.8
CVE-2026-54368

CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to e…

Mitigation only
Fix from $1,950 2026-07-30
Unclassified HIGH 8.6
CVE-2026-54367

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary acc…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-54366

CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary f…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-54365

CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create …

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-54364

CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variabl…

No fix yet
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-54363

CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted token…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.3
CVE-2026-47876

VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileg…

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 7.6
CVE-2026-41703

VMware ESX, Workstation, and Fusion contain an out-of-bounds read vulnerability. A malicious actor with VM deployment privileges could trigger an out…

No fix yet
Fix from $1,950 2026-07-30
Cost Management Metrics Operator MEDIUM 6.8
CVE-2026-18382

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows a user able to edit the CR to specify an…

No fix yet
Fix from $1,600 2026-07-30
Cost Management Metrics Operator HIGH 7.6
CVE-2026-18381

A flaw was found in the koku-metrics-operator for Red Hat OpenShift. The operator's CostManagementMetricsConfig custom resource allows a user able to…

No fix yet
Fix from $1,950 2026-07-30
Cost Management Metrics Operator MEDIUM 6.8
CVE-2026-18378

A flaw was found in koku-metrics-operator. The operator's CostManagementMetricsConfig custom resource allows user able to edit the CR to specify an a…

No fix yet
Fix from $1,600 2026-07-30