Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.3 CVE-2026-66154 An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-66150 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-66149 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.3 CVE-2026-66148 An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.4 CVE-2026-66147 An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote… No fix yet Fix from $5,7502026-08-11 HIGH 7.1 CVE-2026-63177 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-63134 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-63133 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-55676 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a… No fix yet Fix from $4,9002026-08-11 HIGH 8.2 CVE-2026-19550 A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administratio… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-29035 CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remot… No fix yet Fix from $4,0002026-08-11 HIGH 8.4 CVE-2026-18634 An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-15606 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-14863 FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.3 CVE-2026-71845 A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.0 CVE-2026-71475 A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.3 CVE-2026-71474 A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-71468 A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token … No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-71467 A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.1 CVE-2026-66146 Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker … No fix yet Fix from $4,0002026-08-11 CRITICAL 9.1 CVE-2026-66145 An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke… No fix yet Fix from $5,7502026-08-11 HIGH 8.7 CVE-2026-48813 Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralizati… No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-45618 LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa… No fix yet Fix from $5,7502026-08-11 HIGH 8.1 CVE-2026-18844 The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These command… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-16230 The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-13457 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48809 python-engineio is a Python implementation of the Engine.IO realtime client and server. Versions prior to 4.13.2 have two specific configurations of … No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48802 python-engineio is a Python implementation of the Engine.IO realtime client and server. Prior to version 4.13.2, an attacker can cause the creation o… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-18712 An issue in MongoDB Server's Queryable Encryption maintenance operations could allow an authenticated user with privileges on one encrypted collectio… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18711 An issue in MongoDB Server's query execution engine could allow an authenticated user with read and write privileges to cause an internal reference t… No fix yet Fix from $4,9002026-08-11