Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Sed MEDIUM 6.5
CVE-2026-9154

Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content t…

Mitigation only
Fix from $1,600 2026-06-25
Sed MEDIUM 6.5
CVE-2026-9153

Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 8.1
CVE-2026-55762

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, th…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.4
CVE-2026-55759

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Ro…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-55666

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.0
CVE-2026-55570

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, descri…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 8.7
CVE-2026-54759

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-54158

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolate…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 7.1
CVE-2026-54070

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar packag…

No fix yet
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.2
CVE-2026-54069

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-ext…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified MEDIUM 5.9
CVE-2026-54068

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from auth…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-54067

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <st…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 7.5
CVE-2026-54066

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding"…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.9
CVE-2026-50551

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in t…

Mitigation only
Fix from $2,300 2026-06-24
Gimp HIGH 7.8
CVE-2026-2050

GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.3
CVE-2026-7539

A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow esc…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.5
CVE-2026-52815

Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/or…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.8
CVE-2026-52809

Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-a…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.5
CVE-2026-52799

Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.5
CVE-2026-52797

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-50129

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-50128

Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let website…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.7
CVE-2026-49278

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.1…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-46423

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-45689

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-45688

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 8.5
CVE-2026-45687

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.7
CVE-2026-45677

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.3
CVE-2026-33543

FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/creat…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 7.7
CVE-2026-33235

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.5…

Mitigation only
Fix from $1,950 2026-06-24