Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-66898 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing … No fix yet Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-19654 A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.5 CVE-2026-19502 MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-19130 A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub clust… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-19004 An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored proced… No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-19002 A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write … No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-19001 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, sche… No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-18888 The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buf… No fix yet Fix from $4,0002026-08-12 HIGH 8.5 CVE-2026-16033 A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image me… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-13622 A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-13367 IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. Informix Dynamic Server No fix yet Fix from $4,9002026-08-12 HIGH 8.7 CVE-2026-73332 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers t… No fix yet Fix from $4,9002026-08-12 HIGH 7.1 CVE-2026-73331 CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges … No fix yet Fix from $4,9002026-08-12 MEDIUM 6.6 CVE-2026-73330 CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by e… No fix yet Fix from $4,0002026-08-12 HIGH 8.7 CVE-2026-73329 CamaleonCMS contains a stored cross-site scripting vulnerability that allows authenticated low-privileged users to execute arbitrary JavaScript in an… No fix yet Fix from $4,9002026-08-12 HIGH 7.6 CVE-2026-73326 CamaleonCMS contains a missing authorization vulnerability that allows any authenticated low-privileged user to access and modify plugin settings by … No fix yet Fix from $4,9002026-08-12 HIGH 8.2 CVE-2026-73303 Budibase is an open-source low-code platform. Prior to 3.40.0, POST /api/v2/email on account.budibase.app accepted a client-controlled accountId with… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-73269 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, … No fix yet Fix from $5,7502026-08-12 CRITICAL 9.9 CVE-2026-73268 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat… No fix yet Fix from $5,7502026-08-12 HIGH 8.0 CVE-2026-72809 SiYuan versions <= v3.7.2 (patched in v3.7.4) contain an authentication bypass vulnerability in the kernel's CheckAuth function, which grants the adm… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72808 SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api/asset/getFileAnnotation endp… No fix yet Fix from $4,0002026-08-12 HIGH 8.0 CVE-2026-72807 SiYuan versions before v3.7.4 contain a second-order SQL injection vulnerability in attribute-view template columns that expose the queryBlocks funct… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72806 SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter that fails to check publish pass… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72805 SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeInfos endpoints, allowing disc… No fix yet Fix from $4,0002026-08-12 HIGH 8.6 CVE-2026-72804 SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing anonymous readers to retrieve … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72803 SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoints. Attackers can retrieve blo… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-72802 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the resolveAssetPath endpoint that returns absolute filesystem paths… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-72801 SiYuan versions before v3.7.4 disclose encrypted-notebook key-derivation material and wrapped data keys through unauthenticated endpoints in publish … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.8 CVE-2026-72800 SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing authenticated readers to retr… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-72799 SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoints (getFullHPathByID, getHPa… No fix yet Fix from $4,0002026-08-12