Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-76217 GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove() and Head.checkout(). Attac… Fix unknown Fix from $4,0002026-08-19 HIGH 7.5 CVE-2026-76216 Vikunja through 2.4.0 contains a principal-type confusion vulnerability where LinkSharing principals with id N are treated as user principals with us… Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-76215 phpMyFAQ before 4.1.7 fails to apply parent FAQ visibility checks before returning child resources including comments and attachments. Unauthenticate… Fix unknown Fix from $4,0002026-08-19 HIGH 7.4 CVE-2026-76214 phpMyFAQ before 4.1.7 (affected versions <= 4.1.5) fails to persist the WebAuthn login challenge generated by prepareForLogin, because neither WebAut… Fix unknown Fix from $4,9002026-08-19 HIGH 7.4 CVE-2026-76213 phpMyFAQ before 4.1.7 contains a brute-force vulnerability in the two-factor authentication step where the failure counter is session-scoped and rese… Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-76212 phpMyFAQ before 4.1.7, when configured to use PostgreSQL via the native pgsql PHP extension, declares an incorrect LIKE ESCAPE character ('=') in the… Fix unknown Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-76210 phpMyFAQ before 4.1.7 does not adequately sanitize HTML in FAQ answers before generating PDFs via TCPDF. An attacker with permission to create or edi… Fix unknown Fix from $4,0002026-08-19 HIGH 8.2 CVE-2026-76208 phpMyFAQ versions 3.1.0 through 4.1.6 contain an authentication bypass vulnerability in AuthLdap::create(). When LDAP authentication is enabled, afte… Fix unknown Fix from $4,9002026-08-19 HIGH 8.1 CVE-2026-76207 phpMyFAQ before 4.1.7 contains a two-factor authentication bypass vulnerability where remember-me tokens are issued before 2FA verification completes… Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-76206 phpMyFAQ versions before 4.1.7 fail to validate active status in the PDF export endpoint, allowing unauthenticated attackers to retrieve draft FAQ me… Fix unknown Fix from $4,0002026-08-19 HIGH 8.1 CVE-2026-76205 phpMyFAQ before 4.1.7 contains a SQL injection vulnerability in the glossary create and update endpoints caused by truncating an escaped string befor… Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-75920 phpMyFAQ before v4.1.6 writes content backup ZIP archives to the web-accessible document root at content.zip, exposing sensitive files including data… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-75919 phpMyFAQ before 4.1.7 contains an authentication bypass vulnerability in SetupController that allows unauthenticated attackers to run database migrat… Fix unknown Fix from $4,0002026-08-19 HIGH 8.8 CVE-2026-75918 phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers ca… Fix unknown Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-75917 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getL… Fix unknown Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-75916 SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src… Fix unknown Fix from $4,9002026-08-19 MEDIUM 6.1 CVE-2026-75148 cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_validate() that allows remote atta… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.1 CVE-2026-75114 Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed… Fix unknown Fix from $4,0002026-08-19 CRITICAL 9.3 CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is inter… Fix unknown Fix from $5,7502026-08-19 CRITICAL 10.0 CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-s… Fix unknown Fix from $5,7502026-08-19 MEDIUM 6.5 CVE-2026-70424 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne… Fix unknown Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-70423 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privilege… Fix unknown Fix from $4,0002026-08-19 HIGH 8.1 CVE-2026-70422 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… Fix unknown Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-70421 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote … Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.1 CVE-2026-65612 nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an e… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.1 CVE-2026-65611 nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive w… Fix unknown Fix from $4,0002026-08-19 HIGH 7.1 CVE-2026-56088 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… Fix unknown Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-54796 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-54795 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… Fix unknown Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-54794 Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with re… Fix unknown Fix from $4,9002026-08-19