Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-16772

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.9
CVE-2026-13198

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability …

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.3
CVE-2026-13197

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-13196

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in ver…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-58224

A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets a…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19880

Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, …

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-19879

A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing ca…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-53472

A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to sto…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-1621

Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This i…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-19830

A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19828

A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the compo…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-19827

A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.1
CVE-2026-19768

Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73673

Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19826

A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19825

A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19824

A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /go…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19823

A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.8
CVE-2026-73630

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with C…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-73051

actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Leng…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.8
CVE-2026-73049

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden a…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.8
CVE-2026-73048

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifi…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.7
CVE-2026-72859

Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72837

File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers wi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.8
CVE-2026-72835

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72833

The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted o…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72830

Grav API plugin versions before 1.0.13 fail to enforce API key scope caps in ConfigController super-scope gates, allowing scoped keys to write schedu…

No fix yet
Fix from $5,750 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72829

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope-cap bypass in UsersController's create() and update() methods. …

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 7.2
CVE-2026-72828

Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enforce API-key scope caps in InvitationsController. The strip-super and accept-grou…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72827

Grav CMS before 2.0.13 contains a server-side template injection vulnerability in email-action parameters that allows low-privileged page editors to …

No fix yet
Fix from $4,900 2026-08-14