Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I MEDIUM 5.4
CVE-2026-17226

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a denial of service due to an out-o…

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 5.3
CVE-2026-17216

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an integer error when processing DRDA large-object hea…

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 5.3
CVE-2026-17212

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.

No fix yet
Fix from $4,000 2026-08-13
I CRITICAL 9.6
CVE-2026-17101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

No fix yet
Fix from $5,750 2026-08-13
I HIGH 7.3
CVE-2026-17099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to improper authentication.

No fix yet
Fix from $4,900 2026-08-13
I MEDIUM 5.3
CVE-2026-17078

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to resource exhaustion.

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 5.3
CVE-2026-17077

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to the use of an uninitialized variable.

No fix yet
Fix from $4,000 2026-08-13
I MEDIUM 5.3
CVE-2026-17076

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to improper processing of DRDA and DDM resynchronization …

No fix yet
Fix from $4,000 2026-08-13
I HIGH 8.2
CVE-2026-17075

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized operations due to improper valida…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.3
CVE-2026-73669

The Signify Philips Hue Bridge Pro firmware embeds a Mosquitto MQTT broker service that listens on all network interfaces without authentication. An …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73531

django-helpdesk before 2.3.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject arbitrary JavaScrip…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.7
CVE-2026-73530

Flyto2 Core before 2.28.0 contains a server-side request forgery guard bypass vulnerability that allows attackers to reach internal services by suppl…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72687

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged opaque identifier. Elasticsea…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72686

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-supplied input. A specific in…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72684

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request containing a crafted user-supplied…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72683

A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API endpoint (https://www.elastic.c…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72681

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kibana feature before it creates …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72680

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied input, and the ownership check on…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72679

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an intervals query. Compiling a deeply …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72678

Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memory for an internal data struct…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.3
CVE-2026-72677

Relative Path Traversal (CWE-23) in Kibana can lead to the unauthorized deletion of Kibana resources via Relative Path Traversal (CAPEC-139). Kibana …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72676

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker-supplied script content via …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.1
CVE-2026-72675

Missing Authorization (CWE-862) in Kibana can lead to cross-space information disclosure and unauthorized data modification via Privilege Abuse (CAPE…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72674

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A user…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-72673

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Accessing Functionality Not Properl…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.7
CVE-2026-72672

The Elastic Security capability that suggests existing field values while a user authors endpoint policy artifacts queries Elastic Defend event data …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.7
CVE-2026-72670

A lower privileged user who holds only the privilege to read agent policies can read the entire configuration of a configured Fleet proxy. This would…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.6
CVE-2026-72669

The state that Kibana stores for an Observability Onboarding flow is not bound to the user who created the flow, and the routes that read and update …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-72667

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). A spec…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-72666

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against Elastic Agents that are assigne…

No fix yet
Fix from $4,000 2026-08-13