Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-66794 A flaw was found in the `cluster-proxy-addon` component of Multicluster Engine for Kubernetes. This vulnerability allows an unauthenticated attacker,… Fix unknown Fix from $5,7502026-08-19 HIGH 7.1 CVE-2026-63652 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c … Fix unknown Fix from $4,9002026-08-19 HIGH 7.7 CVE-2026-63633 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_Ensu… Fix unknown Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-63117 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlig… Fix unknown Fix from $4,0002026-08-19 CRITICAL 9.3 CVE-2026-62682 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in s… Fix unknown Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-62681 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.21.0, an unescaped backtick in a… Fix unknown Fix from $5,7502026-08-19 HIGH 7.1 CVE-2026-62680 Orval generates type-safe JavaScript clients in TypeScript from OpenAPI v3 and Swagger v2 specifications. Prior to 8.22.0, Orval resolves remote and … Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-61518 ISPConfig contains an authenticated SQL injection vulnerability in the Remote API. The primary_id parameter passed to delete and update API methods i… Fix unknown Fix from $4,9002026-08-19 MEDIUM 6.1 CVE-2026-55648 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calcu… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.4 CVE-2026-55564 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whe… Fix unknown Fix from $4,0002026-08-19 HIGH 8.7 CVE-2026-55194 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c en… Fix unknown Fix from $4,9002026-08-19 HIGH 8.7 CVE-2026-55193 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmi… Fix unknown Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-55192 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the… Fix unknown Fix from $4,9002026-08-19 HIGH 8.7 CVE-2026-55191 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder … Fix unknown Fix from $4,9002026-08-19 CRITICAL 9.0 CVE-2026-32475 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor … Fix unknown Fix from $5,7502026-08-19 HIGH 7.5 CVE-2026-19875 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound … Fix unknown Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-19653 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper handling of memory page table… Fix unknown Fix from $4,0002026-08-19 HIGH 8.2 CVE-2026-19234 Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, and FW1060.00 through FW1060.80 is affected by a vulnerability in the host firmware bo… Fix unknown Fix from $4,9002026-08-19 MEDIUM 6.2 CVE-2026-18874 A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into … Fix unknown Fix from $4,0002026-08-19 HIGH 7.1 CVE-2026-17183 An authenticated user with permission to create or edit alert rules can bypass datasource query authorization by marking an alert rule query as a ser… Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2025-14603 The application component processes user-supplied parameters insecurely, passing them into SQL queries. This can enable blind SQL injection, potentia… Fix unknown Fix from $4,9002026-08-19 CRITICAL 9.3 CVE-2025-14600 An insecure deserialization vulnerability in vsDesk allows a remote attacker to gain unauthorized administrative access. By manipulating application … Fix unknown Fix from $5,7502026-08-19 HIGH 7.1 CVE-2026-75147 FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The keyframe detection loop that se… Fix unknown Fix from $4,9002026-08-19 HIGH 8.1 CVE-2026-75146 FFmpeg before commit 65b0dab contains an out-of-bounds read in the DASH demuxer (libavformat/dashdec.c). When a live DASH manifest is refreshed with … Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.8 CVE-2026-75145 FFmpeg before commit b4c199c contains an incorrect integer narrowing conversion in the AV1 RTP packetizer (libavformat/rtpenc_av1.c). The OBU size is… Fix unknown Fix from $4,0002026-08-19 HIGH 7.8 CVE-2026-75144 FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerability in the VC-2/Dirac RTP packetizer (libavformat/rtpenc_vc2hq.c) that allows … Fix unknown Fix from $4,9002026-08-19 CRITICAL 9.8 CVE-2026-75143 FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RIST protocol reader (libavformat/librist.c). librist_read() ignored its size arg… Fix unknown Fix from $5,7502026-08-19 HIGH 7.8 CVE-2026-75142 FFmpeg before commit 9d786e4 contains a stack buffer overflow in the MPEG-PS muxer (libavformat/mpegenc.c). When muxing input with more streams than … Fix unknown Fix from $4,9002026-08-19 HIGH 7.8 CVE-2026-75141 FFmpeg before commit acf5d7c contains a heap buffer overflow in the hvcC box writer. When writing an HEVC configuration record with more NAL units of… Fix unknown Fix from $4,9002026-08-19 CRITICAL 9.0 CVE-2026-72530 A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, … Fix unknown Fix from $5,7502026-08-19