Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-19546 A flaw was found in DBI. This is a fix for a partial fix for CVE-2026-14380 for RHEL 9.8.z and 10.2.z. For a detailed Statement, Description and Mit… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-18640 The NewNotebook API does not sufficiently sanitize its parameters allowing an authenticated user with NOTEBOOK_EDIT permission to write the notebook … No fix yet Fix from $4,9002026-08-11 HIGH 7.3 CVE-2026-18639 When Velociraptor is configured to use an OIDC IdP for authentication, it uses the email claim as a username. However, some IdP allow users to change… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-18638 Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server process with a single request, by c… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-14180 A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.8 CVE-2026-18636 The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users from reading sensitive files or… No fix yet Fix from $4,0002026-08-11 HIGH 7.2 CVE-2026-18635 Velociraptor's VQL has a query() plugin which allows running a VQL query in a different org or user context. To be able to run as a different user, t… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-18129 Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attack… No fix yet Fix from $4,9002026-08-11 HIGH 7.7 CVE-2026-18127 External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write contr… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-18125 An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent serv… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.2 CVE-2026-17535 Velociraptor's NTFS parsing library mishandles several out of bound and memory exhaustion bugs which may be triggered by maliciously crafted NTFS ima… No fix yet Fix from $4,0002026-08-11 CRITICAL 10.0 CVE-2026-17061 A Deserialization of Untrusted Data vulnerability affecting SIMULIA Execution Engine from Release 2023 through Release 2026 could lead to an unauthen… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.8 CVE-2026-51584 An issue in usememos v0.27.1 allows a remote attacker to achieve account takeover via the ssoCredentials branch of the SignIn handler in server/route… No fix yet Fix from $5,7502026-08-11 HIGH 8.5 CVE-2026-51583 An issue in usememos through v0.30.0 allows a remote authenticated attacker to perform Server-Side Request Forgery (SSRF) via the Webhook validation … No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-48056 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 improperly validate executable pat… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.3 CVE-2026-48046 Streambert is a cross-platform Electron Desktop App to stream and download video content. Versions prior to 2.5.0 contain an unvalidated auto-updater… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.8 CVE-2026-46670 YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::creat… No fix yet Fix from $5,7502026-08-11 MEDIUM 5.4 CVE-2026-72784 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.2 CVE-2026-72783 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContain… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72782 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-72781 Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechan… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-72780 Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-72778 Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the … No fix yet Fix from $4,9002026-08-11 MEDIUM 5.8 CVE-2026-72775 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifi… No fix yet Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-72774 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access… No fix yet Fix from $4,9002026-08-11 HIGH 8.9 CVE-2026-72772 n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming to… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72771 n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoin… No fix yet Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-72770 n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.1 CVE-2026-72769 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to creat… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.4 CVE-2026-72768 n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated use… No fix yet Fix from $4,0002026-08-11