Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-72564 An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in … No fix yet Fix from $2,3002026-08-10 MEDIUM 5.3 CVE-2026-71394 GNU Emacs for Android improperly validates the table header input in sfnt_read_table_directory() in src/sfnt.c. Due to an incorrect comparison variab… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-71393 GNU Emacs for Android is vulnerable to an integer overflow in sfnt_read_name_table() in src/sfnt.c. The function computes an allocation size using a … No fix yet Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-71392 GNU Emacs for Android is vulnerable to an integer overflow in the sfnt_read_cmap_format_12() function in src/sfnt.c. When processing a crafted TrueTy… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-71391 GNU Emacs for Android contains an off-by-one error in the gvar table parser in src/sfnt.c. The shared-coordinate index boundary check in sfnt_vary_si… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.4 CVE-2026-66642 Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella allows Cross Site Request Forgery. This issue affects WP Umbrella: from 2.24.2 throug… No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-59087 A flaw was found in the GIMP image manipulation program, specifically within its Seattle Filmworks file loader. A remote attacker could exploit this … Enterprise Linux No fix yet Fix from $1,9502026-08-10 CRITICAL 10.0 CVE-2026-66915 Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the aja… No fix yet Fix from $2,3002026-08-10 HIGH 7.5 CVE-2026-44630 Improper validation of length fields in the Apache IoTDB RPC service may allow a remote unauthenticated attacker to cause a denial of service. By sen… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-19404 A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operations perform no authorization … No fix yet Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-66411 DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unauthenticated attacker may conne… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-66409 DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password may be analyzed and obtained to… No fix yet Fix from $1,6002026-08-10 HIGH 8.1 CVE-2026-66407 DEEBOT PRO M1 and DEEBOT PRO K1VAC improperly implement authentication in WebSocket communication. The WebSocket private key may be retrieved throug… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-66405 DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the telnet servers enabled. The telnet service may be leveraged to log in to the affected products. No fix yet Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-66404 DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activity logs stored on the affecte… No fix yet Fix from $1,6002026-08-10 HIGH 7.5 CVE-2026-66403 DEEBOT PRO M1 and DEEBOT PRO K1VAC leave the web server for debugging purposes enabled. The floor map and log information stored on the affected prod… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.9 CVE-2026-21084 Improper access control in SmartThings prior to version 1.8.47.24 allows local attackers to access sensitive information. No fix yet Fix from $1,6002026-08-10 MEDIUM 5.1 CVE-2026-21081 Improper export of android application components in SamsungPassAutofill prior to version 5.2.10.x allows local attackers to access sensitive informa… No fix yet Fix from $1,6002026-08-10 MEDIUM 5.3 CVE-2026-21075 Improper authorization in handler for custom URL scheme in My Galaxy prior to version 6.3 allows remote attackers to access sensitive information. No fix yet Fix from $1,6002026-08-10 HIGH 7.2 CVE-2026-21074 Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local attackers to execute arbitrary commands with Bixby privilege. No fix yet Fix from $1,9502026-08-10 MEDIUM 6.1 CVE-2026-21073 Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 allows physical attackers to launch arbitrary activity. Android No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-21072 Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. Android No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-21071 Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. Android No fix yet Fix from $1,9502026-08-10 MEDIUM 5.1 CVE-2026-21070 Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensitive information. No fix yet Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-21069 Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds… Android No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-21068 Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 allows privileged local attackers to execute arbitrary code. Android No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-21065 Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. Android No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-21067 Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. Android No fix yet Fix from $1,9502026-08-10 HIGH 7.8 CVE-2026-21066 Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 Release 1 allows local attackers to write out-of-bounds memory. Android No fix yet Fix from $1,9502026-08-10 MEDIUM 5.5 CVE-2026-21064 Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows local attackers to cause device inoperability. Android No fix yet Fix from $1,6002026-08-10