Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.1
CVE-2026-57896

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-38158

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-36425

An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.1
CVE-2026-44019

Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-11889

SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an aut…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.1
CVE-2024-34268

EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connectio…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.7
CVE-2024-32387

An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the communi…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.3
CVE-2024-32386

Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive in…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-63397

remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary J…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.0
CVE-2026-61389

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL requ…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-60140

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.0
CVE-2026-60063

An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL requ…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-15352

A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segme…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-47084

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-47082

An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacat…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.7
CVE-2026-46687

Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter f…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.5
CVE-2026-46686

Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php …

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 10.0
CVE-2026-45336

HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,…

No fix yet
Fix from $2,300 2026-07-16
Unclassified MEDIUM 5.7
CVE-2026-15737

AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore p…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 7.0
CVE-2026-9046

A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in …

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-6511

During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that cou…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.6
CVE-2026-63088

stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypas…

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-63087

Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sen…

No fix yet
Fix from $2,300 2026-07-16
Unclassified HIGH 8.6
CVE-2026-63086

text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completi…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-63085

Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate…

No fix yet
Fix from $1,950 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-3031

Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated …

No fix yet
Fix from $2,300 2026-07-16
Unclassified HIGH 8.8
CVE-2026-14371

The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.3
CVE-2026-13104

A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated use…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.3
CVE-2026-13103

A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local au…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.0
CVE-2026-10589

A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode.

No fix yet
Fix from $1,600 2026-07-16