Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-18618 A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service … No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18617 A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-18611 A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such … No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2026-18608 A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privile… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-16456 A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the … No fix yet Fix from $1,6002026-08-10 HIGH 8.0 CVE-2026-15581 A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and dire… No fix yet Fix from $1,9502026-08-10 HIGH 8.1 CVE-2026-15467 A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by … No fix yet Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-14450 A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP head… No fix yet Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-13717 A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72882 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, an authenticated user who can create or update file mounts for … No fix yet Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-69118 Cachet through 2.4.1 contains a server-side template injection vulnerability in incident template rendering that allows authenticated users to execut… No fix yet Fix from $1,9502026-08-10 HIGH 8.2 CVE-2026-14886 Vault Enterprise's identity entity batch-delete endpoint is vulnerable to a cross-namespace authorization bypass that may allow an authenticated call… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2025-15683 TBEA TLogger V2.1.0.0B0.0.0.0 contains multiple unauthenticated denial-of-service vulnerabilities in its web server. An unauthenticated remote attack… No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2025-15682 TBEA TLogger V2.1.0.0B0.0.0.0 contains an unauthenticated resource exhaustion vulnerability in its web server. An unauthenticated remote attacker can… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.2 CVE-2025-15681 TBEA TLogger V2.1.0.0B0.0.0.0 contains an authentication bypass in its web server. After a user has previously authenticated to the device, an unauth… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2025-13294 An unauthenticated SQL injection vulnerability exists in the web server of TBEA TLogger V2.1.0.0B0.0.0.0. Multiple HTTP endpoints incorporate attacke… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2025-13293 A hard-coded or default root account credential in TBEA TLogger V2.1.0.0B0.0.0.0 allows an unauthenticated remote attacker to obtain root-level acces… No fix yet Fix from $2,3002026-08-10 HIGH 7.5 CVE-2026-71962 Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that … No fix yet Fix from $1,9502026-08-10 MEDIUM 6.6 CVE-2026-6791 When expanding paths that begin with a tilde (~) followed by a username, the internal parse_tilde function extracts the username to determine the use… No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-59091 A flaw was found in GIMP's file format plugins, including those for PSD and PAA files. A remote attacker could exploit these vulnerabilities by trick… Enterprise Linux No fix yet Fix from $1,9502026-08-10 MEDIUM 6.9 CVE-2026-12339 A Zip Slip vulnerability in the WebUI ISP Upgrade functionality allows arbitrary file write via a crafted archive containing directory traversal sequ… No fix yet Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-72900 Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database. No fix yet Fix from $1,6002026-08-10 CRITICAL 10.0 CVE-2026-72899 Metabase allows an unauthenticated attacker to inject arbitrary SQL via a publicly shared card or dashboard that exposes a field-filter (dimension) p… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.6 CVE-2026-72737 Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.8 and earlier, backup.create, backup.update, and backup.restoreBackupWithLogs … No fix yet Fix from $2,3002026-08-10 MEDIUM 6.5 CVE-2026-70622 tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function that allows attackers to read … No fix yet Fix from $1,6002026-08-10 CRITICAL 9.3 CVE-2026-48159 use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicio… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.3 CVE-2026-16626 Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR… No fix yet Fix from $2,3002026-08-10 HIGH 8.6 CVE-2026-10754 Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass s… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.3 CVE-2026-71577 A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared… No fix yet Fix from $1,6002026-08-10 HIGH 8.5 CVE-2026-71576 A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status t… No fix yet Fix from $1,9502026-08-10