Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.2 CVE-2026-56657 Gitea SSH Key Parser Denial of Service No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-55986 Email Management API Bypasses ManageCredentials Feature Restrictions No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes No fix yet Fix from $5,7502026-08-13 HIGH 7.5 CVE-2026-54481 Internal API HTTP client hardcodes InsecureSkipVerify:true with no config override (CWE-295) No fix yet Fix from $4,9002026-08-13 HIGH 8.7 CVE-2026-55402 CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position c… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-42931 Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint No fix yet Fix from $4,0002026-08-13 MEDIUM 6.1 CVE-2026-73671 Saurus CMS Community Edition contains an unauthenticated open redirect vulnerability in the logout handling code in classes/port.inc.php, where the u… No fix yet Fix from $4,0002026-08-13 HIGH 7.2 CVE-2026-73670 A CMS contains a SQL injection vulnerability in admin/db_data.php at line 509 that allows authenticated administrators to inject arbitrary SQL into a… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.3 CVE-2026-73576 In Zimbra Collaboration (ZCS) before 10.1.17, weak cryptographic key generation vulnerability exists in the OnlyOffice integration. The zimbraDocumen… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.1 CVE-2026-73572 In Zimbra Collaboration (ZCS) before 10.1.17, a stored cross-site scripting (XSS) vulnerability exists in the Zimbra Classic Web Client due to insuff… No fix yet Fix from $4,0002026-08-13 HIGH 8.9 CVE-2026-73570 KEV A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP… Zimbra Collaboration Suite No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-73533 Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned upda… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.8 CVE-2026-73532 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned updat… No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-73515 PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplyin… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.9 CVE-2026-55401 CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.0 CVE-2026-55400 CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially … No fix yet Fix from $4,0002026-08-13 HIGH 7.3 CVE-2026-19710 A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70464 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection … No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-70463 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when sp… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-70462 rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disa… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-70461 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-control… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-70460 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-70459 rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daem… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-70458 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-70457 rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-70456 rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70455 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt sh… No fix yet Fix from $4,9002026-08-13 HIGH 8.0 CVE-2026-70454 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70453 rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of … No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-70452 rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS … No fix yet Fix from $4,9002026-08-13