Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.5
CVE-2026-32315

motionEye (mEye) is an online interface for motion software, a video surveillance program with motion detection. Versions prior to 0.44.0 create the …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-31978

motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 ar…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.5
CVE-2026-1840

The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functi…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.6
CVE-2026-11998

A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScr…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.6
CVE-2026-55583

Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-48028

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.6
CVE-2026-47389

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, when using Ruby versions older than …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-46349

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, Mastodon's normalization of incoming…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.7
CVE-2026-46348

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.10, 4.4.17, and 4.3.23, the list of disallowed IP address ra…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-27708

FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method ac…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.0
CVE-2026-23879

py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Versions 1.1.2 and below c…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-53950

@tryghost/activitypub is Ghost’s social/federation client app. Prior to 3.1.0, the ActivityPub client in Ghost was vulnerable to JavaScript injection…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-53949

Ghost is a Node.js content management system. From 5.46.1 until 6.21.2, the validation applied to filters on the public API endpoints could be partia…

No fix yet
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-53948

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, insufficient validation of the client-supplied Content-Type on Ghost's Admin …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-53947

Ghost is a Node.js content management system. From 5.18.0 until 6.21.1, a discrepancy in responses from the members signin endpoints made it possible…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-53946

Ghost is a Node.js content management system. From 6.19.4 until 6.21.1, when re-rendering posts, Ghost would refetch missing image dimensions by issu…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.8
CVE-2026-53944

Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, when making an external request, it is possible to bypass the IP filter that e…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified CRITICAL 9.6
CVE-2026-53943

Ghost is a Node.js content management system. From until 6.37.0, when Ghost is behind a shared caching layer that results in cached content being sh…

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 8.8
CVE-2026-49247

Jellyfin is an open source self hosted media server. From 10.9.0 until 10.11.10, the POST /ClientLog/Document endpoint accepts the Authorization head…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.7
CVE-2026-49220

Jellyfin is an open source self hosted media server. Prior to 10.11.9, a potential XSS attack exists in Jellyfin which can allow a non-privileged use…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.8
CVE-2026-48793

Jellyfin is an open source self hosted media server. Prior to 10.11.10, a potential FFmpeg argument injection vulnerability exists in the subtitle co…

Mitigation only
Fix from $1,950 2026-06-24
Tapo C200 Firmware MEDIUM 6.5
CVE-2026-12760

A denial-of-service (DoS) vulnerability has been identified in Tapo C200 v3 in the network packet handling logic due to improper handling of IPv4 fra…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.5
CVE-2026-49851

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (app…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.7
CVE-2026-55488

motionEye (mEye) is an online interface for a piece of software called "motion," which is a video surveillance program with motion detection. Version…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.1
CVE-2026-50701

A Reflected Cross-Site Scripting (XSS) vulnerability exists in Frappe Framework version 17.0.0-dev due to improper neutralization of user-controlled …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.6
CVE-2026-49269

Apple M1 GPUs retain register file data between compute shader dispatches from different processes. A sandboxed Metal attacker app can run a GPU read…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.3
CVE-2026-12986

A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacke…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-57298

A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers to hav…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.8
CVE-2026-57296

Jenkins External Workspace Manager Plugin 1.3.2 and earlier does not reject path traversal sequences in the custom workspace path provided to the exw…

No fix yet
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.4
CVE-2026-57292

A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allows attackers to connect to an attacke…

Mitigation only
Fix from $1,600 2026-06-24