Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-66374

Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path.

No fix yet
Fix from $1,950 2026-07-25
Unclassified MEDIUM 6.5
CVE-2026-66339

A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-66338

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs vio…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-66337

A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when …

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.8
CVE-2026-61892

Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges.

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-61886

Weintek cMT3092X HMI stores user account passwords in plaintext.

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-60135

An attacker can modify data that should be restricted to read‑only access.

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.8
CVE-2026-60134

Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges.

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.8
CVE-2026-61884

The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. B…

No fix yet
Fix from $2,300 2026-07-24
Azure Portal HIGH 7.5
CVE-2026-62835

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.1
CVE-2026-54342

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p…

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.1
CVE-2026-48021

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 8.5
CVE-2026-17107

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-eng…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.2
CVE-2026-65711

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.1
CVE-2026-65710

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.3
CVE-2026-65709

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.1
CVE-2026-65708

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-65707

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by …

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.2
CVE-2026-65693

Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary O…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.1
CVE-2026-8789

The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.1
CVE-2026-8308

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W…

No fix yet
Fix from $1,600 2026-07-24
Azure App Service For Linux CRITICAL 9.8
CVE-2026-58630

Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Unclassified CRITICAL 9.8
CVE-2026-58586

Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses…

No fix yet
Fix from $2,300 2026-07-24
Purview Data Governance CRITICAL 10.0
CVE-2026-57106

Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Kubernetes Service CRITICAL 10.0
CVE-2026-56163

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 8.7
CVE-2026-55732

Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and …

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.6
CVE-2026-55731

Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.7
CVE-2026-55730

Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to exec…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.7
CVE-2026-55729

Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthentica…

No fix yet
Fix from $1,950 2026-07-24
Build Of Keycloak MEDIUM 6.5
CVE-2026-17059

A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem…

No fix yet
Fix from $1,600 2026-07-24