Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-73522

COVESA Open1722 through 0.9.2 contains a stack buffer overflow vulnerability that allows unauthenticated remote attackers to write past the end of a …

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-71980

Belledonne Communications bcg729 through 1.1.2 contains an out-of-bounds read vulnerability in the decodeSIDframe() function in src/cng.c that allows…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-59894

sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, sqlparse/filters/output.py fails to escape existing backslashes before quo…

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50772

An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-51346

SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensit…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-50771

Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification…

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50770

An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request.

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50769

The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conf…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50768

File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the …

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.8
CVE-2026-48053

Kolibri is an offline-first education platform. Prior to version 0.19.4, several Kolibri API endpoints accept an unvalidated `baseurl` parameter and …

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 8.1
CVE-2026-33437

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.0.0, the Get Info workflow in app/core/…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-40145

A vulnerability exists in the interaction between a Endpoint Privilege Management (Windows Deployment) support utility and the agent's tamper protect…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 8.4
CVE-2026-75060

In JetBrains PyCharm before 2026.2.1 code execution was possible via unauthenticated Jupyter MCP tools

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-75058

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-75057

In JetBrains IntelliJ IDEA before 2026.1.5 git credentials were written in plaintext to the IDE log

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.8
CVE-2026-75056

In JetBrains IntelliJ IDEA before 2026.2.1 rCE via Markdown export tool was possible

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-75055

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-75054

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the OpenAPI preview proxy in untrusted projects

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-75053

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 8.1
CVE-2026-75051

In JetBrains YouTrack before 2026.2.17917 unauthorised project transfer between organisations was possible

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-75050

In JetBrains YouTrack before 2026.1.13901, 2026.2.17950 doS attack was possible via crafted type parameters

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75049

In JetBrains YouTrack before 2026.1.13903, 2026.2.17950 an authenticated user could read restricted articles from other projects via the draft creat…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 8.2
CVE-2026-75048

In JetBrains YouTrack before 2026.2.18068 stored XSS via the fenced code-block language label was possible

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75047

In JetBrains YouTrack before 2026.2.18177 doS attack was possible via a decompression bomb in the import endpoint

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-75045

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 8.1
CVE-2026-75044

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary enti…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-74858

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/se…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.9
CVE-2026-68762

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-55674

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-53960

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post conte…

No fix yet
Fix from $4,000 2026-08-17