Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-20461

In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected t…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-20460

In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-20459

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-20458

In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connect…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-20457

In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.8
CVE-2026-14191

An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecIte…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54903

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corrupt…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54902

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerable to Use-After-Free when in S…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54901

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mar…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54900

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in usual mode with create_id ena…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54899

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling symbol_keys on a reused Oj::Par…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-54592

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#each_child, when invoked recu…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54502

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-base…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-54500

Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uniniti…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 8.8
CVE-2026-57995

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to gr…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-56700

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 10.0
CVE-2026-56415

Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A re…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 10.0
CVE-2026-56413

Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default a…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-56331

Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors wh…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 6.5
CVE-2026-56328

Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests withou…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-56327

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated atta…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 7.1
CVE-2026-56320

Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validatin…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-56318

Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different e…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-56300

Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity or…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.1
CVE-2026-56286

Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authe…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.6
CVE-2026-56249

Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite ex…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.8
CVE-2026-56247

Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pendin…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.3
CVE-2026-56233

Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to b…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.8
CVE-2026-56230

Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.4
CVE-2026-56224

Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users with…

Mitigation only
Fix from $1,600 2026-06-30