Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-17082 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied … I No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-19311 Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or de… No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-18952 Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user … No fix yet Fix from $4,9002026-08-12 CRITICAL 9.6 CVE-2026-73300 Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru… No fix yet Fix from $5,7502026-08-12 HIGH 8.7 CVE-2026-73298 The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for m… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-69106 A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content. No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-49467 Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass … No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-42018 JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing … No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-16906 IBM i 7.6, and 7.5 could allow a remote authenticated attacker to execute arbitrary commands with elevated privileges due to improper neutralization … I No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-16856 IBM i 7.6, and 7.5 could allow a local attacker to gain elevated privileges due to improper neutralization of special elements used in an OS command. I No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-48554 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to authenticated remote code execution via unfiltered NOTIFICATION-family macr… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-48553 Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable to authenticated remote code execution via custom-variable macro injection thr… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-48552 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js. Unencoded JSON string value… No fix yet Fix from $4,0002026-08-12 HIGH 7.4 CVE-2026-48551 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cook… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.1 CVE-2026-48550 Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An u… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-18847 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i. I No fix yet Fix from $5,7502026-08-12 HIGH 8.8 CVE-2026-18683 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user… I No fix yet Fix from $4,9002026-08-12 HIGH 7.1 CVE-2026-17094 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal… I No fix yet Fix from $4,9002026-08-12 HIGH 8.1 CVE-2026-18098 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XM… I No fix yet Fix from $4,9002026-08-12 HIGH 8.3 CVE-2026-17095 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection. I No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-16694 IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr… I No fix yet Fix from $4,0002026-08-12 HIGH 7.8 CVE-2026-73325 Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by s… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.9 CVE-2026-69107 An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions. No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-69105 An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and … No fix yet Fix from $4,9002026-08-12 HIGH 7.2 CVE-2026-68759 A holder of a valid integration credential may impersonate other users under specific conditions. No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-68758 A low-privileged authenticated user may access restricted support information under specific conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-66384 An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions. No fix yet Fix from $4,0002026-08-12 MEDIUM 6.7 CVE-2026-66016 Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged loca… No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-65941 In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.8 CVE-2026-65940 In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server. No fix yet Fix from $4,0002026-08-12