Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-67960

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, C…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 7.5
CVE-2026-67918

Directory Traversal vulnerability in hermes-studio v.0.6.26 allows a remote attacker to obtain sensitive information via the validatePath function in…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67868

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMonitoredItems processing. This…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67854

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-51977

An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 8.6
CVE-2026-56677

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the …

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-42163

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-11817

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-o…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75482

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75480

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users …

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75479

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to en…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75111

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read ar…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-75110

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, d…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 7.1
CVE-2026-75109

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrup…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-75108

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe …

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-75104

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model d…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 8.8
CVE-2026-75103

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67967

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-448…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67966

Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67965

An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67926

An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-67925

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67917

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-66795

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 8.8
CVE-2026-65640

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisit…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-54356

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts an…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-39255

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-39254

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAu…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 7.8
CVE-2026-34399

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untr…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-19589

Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead t…

No fix yet
Fix from $4,900 2026-08-17