Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-9737

During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.8
CVE-2026-14881

When importing connections in Compass it is possible to override some connection options that are otherwise can't be changed via connection form. In …

No fix yet
Fix from $1,950 2026-07-22
Unclassified CRITICAL 9.6
CVE-2026-16624

Cal.com OSS ships lacks authorization on webhook teamId creation, allowing any authenticated user to create a webhook on any team via unvalidated tea…

No fix yet
Fix from $2,300 2026-07-22
Unclassified HIGH 7.8
CVE-2026-16157

Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY permissions that propagate to all subdirectories. Installing the software outside…

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.8
CVE-2026-7328

Missing authorization in Caliptra Core Runtime Firmware (INVOKE_DPE_MLDSA87, CM_AES_GCM_DECRYPT_DMA, EXTERNAL_MAILBOX_CMD commands) in subsystem mode…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.8
CVE-2026-16615

A flaw was found in librest. The PKCE implementation for OAuth authorization uses the GRand function from the GLib API, a cryptographically insecure …

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.1
CVE-2026-64828

Froiden TableTrack through 1.3.10 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary HTML…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.0
CVE-2026-44276

Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.8
CVE-2026-16607

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalat…

No fix yet
Fix from $1,950 2026-07-22
Unclassified CRITICAL 9.8
CVE-2026-16606

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for unauthenticated remote …

No fix yet
Fix from $2,300 2026-07-22
Unclassified MEDIUM 6.3
CVE-2026-16552

A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d configuration entry that writes to a file, systemd-tmpfiles can follow a symbolic …

No fix yet
Fix from $1,600 2026-07-22
Unclassified CRITICAL 9.8
CVE-2026-2395

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Xpoda Türkiye Informatics Technology Inc. No Co…

No fix yet
Fix from $2,300 2026-07-22
Unclassified HIGH 7.8
CVE-2026-14985

The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains a local privilege escalation vulnerability in the core firmware. This is due to…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 8.6
CVE-2026-13321

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone. This issue affects BIND 9 …

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-13204

If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG for only one of these types, then B…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-12617

The issue is unexpected program termination based on ordering and/or specific content in responses to queries for CNAME or DNAME, and A records. Spec…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-11721

It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone in which the RRSIG is con…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-11622

A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage. The attacker …

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-11605

The issue is a resource exhaustion vulnerability associated with DNSSEC validation. BIND always validates all RRSIG records in an answer, even if the…

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 7.5
CVE-2026-11331

An attacker who knows (or guesses) that a resolver uses RPZ with wildcard CNAME policies can craft query names long enough to trigger a NAMETOOLONG e…

No fix yet
Fix from $1,950 2026-07-22
Unclassified MEDIUM 6.5
CVE-2026-10822

If BIND encounters a particular invalid data structure in a DNS record, it will accept the invalid data, and may subsequently abort and exit. BIND w…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 6.8
CVE-2026-10723

BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affe…

No fix yet
Fix from $1,600 2026-07-22
Unclassified HIGH 7.5
CVE-2026-62145EPSS 8%

A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privi…

No fix yet
Fix from $1,950 2026-07-22
Unclassified CRITICAL 9.1
CVE-2026-62144EPSS 21%

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attac…

No fix yet
Fix from $2,300 2026-07-22
Unclassified MEDIUM 6.3
CVE-2026-50243

In NLnet Labs Unbound 1.6.2 up to and including 1.25.1, when Unbound is configured with the 'respip' module in front of the validator together with a…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.3
CVE-2026-16560

A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap al…

No fix yet
Fix from $1,600 2026-07-22
Unclassified MEDIUM 5.9
CVE-2026-14586

In NLnet Labs Unbound 1.22.0 up to and including 1.25.1, in DNS-over-QUIC environments, with high concurrency and under pressure, an assertion in lib…

No fix yet
Fix from $1,600 2026-07-22
Unclassified CRITICAL 9.3
CVE-2026-8152

Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is dep…

No fix yet
Fix from $2,300 2026-07-22
Unclassified HIGH 7.8
CVE-2026-44191

A flaw was found in the Visual Studio Code Ansible Lightspeed extension. This command injection vulnerability (CWE-78) arises from improper handling …

No fix yet
Fix from $1,950 2026-07-22
Unclassified HIGH 8.8
CVE-2026-65603

The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (pr…

No fix yet
Fix from $1,950 2026-07-22