Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.5
CVE-2026-36908

A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a…

No fix yet
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.5
CVE-2026-36907

A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.5
CVE-2026-36478

An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll,…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.5
CVE-2026-39031

Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.5
CVE-2026-38641

An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted shared …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-38639

An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a cr…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.7
CVE-2026-55189

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read an…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.2
CVE-2026-55188

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-52785

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 8.8
CVE-2026-52784

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.2
CVE-2026-52783

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/Shar…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/projec…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified MEDIUM 6.4
CVE-2026-52781

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants <macro> elements unrestricte…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.6
CVE-2026-52780

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-52779

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 8.6
CVE-2026-49991

RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-47193

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44736

OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44735

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-44734

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenPr…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.9
CVE-2026-44733

OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH requ…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.7
CVE-2026-44696

OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Saniti…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 8.8
CVE-2026-32833

Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-29509

Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.3
CVE-2026-55448

mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local projec…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 8.6
CVE-2026-55441

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.5
CVE-2026-54557

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.6
CVE-2026-33646

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template eng…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 8.8
CVE-2026-57518

Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate…

Mitigation only
Fix from $1,950 2026-06-26