Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-14182 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.4 CVE-2026-72506 VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a commun… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-18728 A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration P… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-0299 Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHOR… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.2 CVE-2026-0298 An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.2 CVE-2026-0297 A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gatew… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.0 CVE-2026-0294 A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to exe… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.6 CVE-2026-0293 A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tampe… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-50544 NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default ins… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-49473 @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by ma… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.9 CVE-2026-46688 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can … No fix yet Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-46382 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local U… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.8 CVE-2026-71194 In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones … No fix yet Fix from $4,0002026-08-12 CRITICAL 9.6 CVE-2026-71193 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.6 CVE-2026-49481 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.5 CVE-2026-47718 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-47717 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensiti… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-15141 The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, … No fix yet Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-73519 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs,… No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-71846 A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch perm… No fix yet Fix from $4,0002026-08-12 HIGH 8.5 CVE-2026-71473 A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerabil… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.0 CVE-2026-71471 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search … No fix yet Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-71469 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique tok… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-19003 A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-18727 A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Conf… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18726 A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in t… No fix yet Fix from $4,0002026-08-12 HIGH 8.2 CVE-2026-17485 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. I No fix yet Fix from $4,9002026-08-12 CRITICAL 10.0 CVE-2024-27253 IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. No fix yet Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-65370 ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed… No fix yet Fix from $4,9002026-08-12