Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-64545

In the Linux kernel, the following vulnerability has been resolved: net, bpf: check master for NULL in xdp_master_redirect() xdp_master_redirect() …

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.8
CVE-2026-64543

In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() bearer_disable() …

No fix yet
Fix from $1,950 2026-07-27
Unclassified CRITICAL 9.8
CVE-2026-64541

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handl…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 8.1
CVE-2026-64540

In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() genelink_rx_fixup…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.8
CVE-2026-64539

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD eir_create_adv…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.2
CVE-2026-12001

A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & A…

No fix yet
Fix from $1,600 2026-07-27
Enterprise Linux HIGH 7.1
CVE-2026-66759

A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data…

No fix yet
Fix from $1,950 2026-07-27
Enterprise Linux HIGH 7.8
CVE-2026-66758

A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bi…

No fix yet
Fix from $1,950 2026-07-27
Enterprise Linux MEDIUM 5.5
CVE-2026-66757

A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image …

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-66031

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 7.5
CVE-2026-51244

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in UnpackFrameHeader(). Multiple attacker-controlled index parameters are used …

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.9
CVE-2026-17612

Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vuln…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 7.5
CVE-2026-12383

A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowA…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-66030

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to injec…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 5.4
CVE-2026-66029

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject…

No fix yet
Fix from $1,600 2026-07-27
Unclassified MEDIUM 6.7
CVE-2026-66028

Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to cr…

No fix yet
Fix from $1,600 2026-07-27
Unclassified CRITICAL 9.8
CVE-2026-55579

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, Pheditor ships with a hardcoded default…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 8.8
CVE-2026-55578

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.6, the terminal feature in Pheditor uses a…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 8.8
CVE-2026-54540

Pheditor is a single-file editor and file manager written in PHP. Prior to version 2.0.5, there is an authenticated terminal command whitelist bypass…

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 6.9
CVE-2026-54272

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Versions 10.1.1 through 10.2.0 are vulnerable to SSRF thr…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 8.8
CVE-2026-51235

LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function (src/libraw_cxx.cpp) and fuji_rotate() function (src/decoders/fuji.cpp).

No fix yet
Fix from $1,950 2026-07-27
Unclassified CRITICAL 9.9
CVE-2026-48030EPSS 5%

Pheditor is a single-file editor and file manager written in PHP. From version 2.0.1 to before version 2.0.4, an OS Command Injection vulnerability i…

No fix yet
Fix from $2,300 2026-07-27
Unclassified HIGH 7.5
CVE-2026-66731

facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerability in the HTTP/1.1 chunked transfer encoding parser that allows unauthenticated …

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.5
CVE-2026-66730

facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerability in the multipart body parser that allows an unauthenticated remote attacker t…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.5
CVE-2026-66729

facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerability in the multipart MIME body parser that allows unauthenticated remote attacke…

No fix yet
Fix from $1,950 2026-07-27
Unclassified HIGH 7.8
CVE-2026-24252

NVIDIA NeMo for Linux contains a vulnerability where an attacker may cause OS command injection. A successful exploit of this vulnerability may lead …

No fix yet
Fix from $1,950 2026-07-27
Unclassified MEDIUM 5.0
CVE-2026-17531

A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Affected by this issue is some unknown functionality of the file server/src/route…

No fix yet
Fix from $1,600 2026-07-27
Unclassified HIGH 8.5
CVE-2026-17192

A VCO feature does not sufficiently validate caller-supplied input, allowing requests to be made on behalf of authenticated tenant accounts to intern…

No fix yet
Fix from $1,950 2026-07-27
Unclassified CRITICAL 9.1
CVE-2026-17191

An input validation vulnerability exists in an API component of the orchestrator. An authenticated user can exploit this flaw to manipulate backend q…

No fix yet
Fix from $2,300 2026-07-27
Unclassified MEDIUM 6.5
CVE-2026-66399

phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in GroupController::updateMembers() that allows administrators with only group-ma…

No fix yet
Fix from $1,600 2026-07-27