Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-72545 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any con… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72544 An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-72543 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any con… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-72542 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job met… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72541 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource t… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-72539 An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless … No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-72538 An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone … No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72537 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-72536 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subs… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-72535 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessio… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72534 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-72533 An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization … No fix yet Fix from $4,9002026-08-11 HIGH 7.4 CVE-2026-50237 A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelm… No fix yet Fix from $4,9002026-08-11 HIGH 7.4 CVE-2026-50236 An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without … No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-13739 A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.2 CVE-2026-13738 CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.2 CVE-2026-13737 CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance … No fix yet Fix from $5,7502026-08-11 CRITICAL 10.0 CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function… No fix yet Fix from $5,7502026-08-11 MEDIUM 6.0 CVE-2026-33922 A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an i… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.2 CVE-2026-33921 The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local… No fix yet Fix from $4,0002026-08-11 HIGH 7.1 CVE-2026-72694 A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can expl… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-72693 `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `k… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-15567 A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-contro… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-15565 A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class th… No fix yet Fix from $4,9002026-08-11 HIGH 7.4 CVE-2026-15563 A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI l… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-15562 A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-r… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-15561 A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthentica… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-15560 when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an… No fix yet Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-15556 A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow a… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-15555 A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River u… No fix yet Fix from $4,9002026-08-11