Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2026-15554 the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-10579 A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe… No fix yet Fix from $5,7502026-08-11 MEDIUM 6.5 CVE-2026-19391 A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. Th… No fix yet Fix from $1,6002026-08-11 HIGH 8.5 CVE-2026-16053 Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exch… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.3 CVE-2026-8158 The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.1 CVE-2026-6505 The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-6181 The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.7 CVE-2026-5304 An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.7 CVE-2026-5303 The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner… No fix yet Fix from $1,6002026-08-11 HIGH 7.2 CVE-2026-4757 A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-14548 The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an… No fix yet Fix from $1,6002026-08-11 CRITICAL 9.1 CVE-2026-19516 A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-19425 Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb… No fix yet Fix from $2,3002026-08-11 MEDIUM 6.4 CVE-2026-16974 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S… No fix yet Fix from $1,6002026-08-11 HIGH 8.4 CVE-2026-8917 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a spe… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-24330 A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un… No fix yet Fix from $1,6002026-08-11 HIGH 7.5 CVE-2026-19424 Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.3 CVE-2026-66779 Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.3 CVE-2026-66778 SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-66777 SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-66776 SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-66773 A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.1 CVE-2026-66771 SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user … No fix yet Fix from $1,6002026-08-11 MEDIUM 6.3 CVE-2026-66770 Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag… No fix yet Fix from $1,6002026-08-11 HIGH 7.9 CVE-2026-66763 SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.4 CVE-2026-66760 SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from … No fix yet Fix from $1,6002026-08-11 MEDIUM 6.5 CVE-2026-58248 SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.3 CVE-2026-58247 SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This could disclose limited, non-sensi… No fix yet Fix from $1,6002026-08-11 HIGH 8.8 CVE-2026-58243 SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to exe… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.9 CVE-2026-58238 SAP Approuter does not sufficiently handle certain requests under specific conditions. An unauthenticated attacker could send specially crafted input… No fix yet Fix from $1,6002026-08-11