Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-63623 A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.4 CVE-2026-56619 HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controll… No fix yet Fix from $1,6002026-08-10 HIGH 8.8 CVE-2026-66738 SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-type… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.3 CVE-2026-48158 use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.1 CVE-2026-18412 OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these… No fix yet Fix from $2,3002026-08-10 CRITICAL 9.8 CVE-2026-63106 ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr… No fix yet Fix from $2,3002026-08-10 MEDIUM 5.4 CVE-2026-63105 ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML p… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.1 CVE-2026-18478 Magnolia CMS is vulnerable to Stored XSS in import functionality. An attacker with editor privileges can inject arbitrary HTML and JS into the name o… No fix yet Fix from $1,6002026-08-10 MEDIUM 6.7 CVE-2026-16742 systemd-homed contains a local privilege escalation bug via arbitrary system group addition to a local, logged in, homed-managed user No fix yet Fix from $1,6002026-08-10 MEDIUM 5.5 CVE-2026-15059 Local unprivileged users can terminate arbitrary local processes via a systemd-oomd IPC API due to a missing path traversal validation. No fix yet Fix from $1,6002026-08-10 HIGH 7.5 CVE-2026-72692 A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-72691 An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-sig… No fix yet Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-72690 An improper authorization vulnerability in Attendize through commit 9289acb allows an authenticated remote attacker to inject persistent mandatory su… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-72689 A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read com… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-72688 A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stor… No fix yet Fix from $1,9502026-08-10 HIGH 7.3 CVE-2026-6374 Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601 allows Read Sensitive Constants Within an Executable. This issue affects WAH76… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-6373 Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allows Web Application Fingerprint… No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-68427 In the Linux kernel, the following vulnerability has been resolved: gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings __host1x_bo_… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.8 CVE-2026-68426 In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segme… No fix yet Fix from $2,3002026-08-10 HIGH 7.1 CVE-2026-68425 In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP rec… No fix yet Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-68420 In the Linux kernel, the following vulnerability has been resolved: xfrm: reject optional IPTFS templates in outbound policies syzbot reported a st… No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68419 In the Linux kernel, the following vulnerability has been resolved: RDMA/irdma: Prevent rereg_mr for non-mem regions When a QP/CQ/SRQ is created, a… No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68417 In the Linux kernel, the following vulnerability has been resolved: RDMA/siw: publish QP after initialization siw_create_qp() currently calls siw_q… No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68415 In the Linux kernel, the following vulnerability has been resolved: xfrm: clear mode callbacks after failed mode setup xfrm_state_gc_task can run l… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-68414 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: cancel sched scan results work on unregister cfg80211_sched_sca… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-68409 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: defer link RX stats percpu free to RCU sta_remove_link() frees … No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68404 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: use wiphy work for socket owner autodisconnect nl80211_netlink_… No fix yet Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-68402 In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: bound element ID read when checking non-inheritance cfg80211_is… No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68401 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() Sashiko … No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-68400 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation Use… No fix yet Fix from $1,9502026-08-10