Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-70630 FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (li… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.5 CVE-2026-70629 FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec… No fix yet Fix from $1,6002026-08-06 HIGH 7.8 CVE-2026-70628 FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsu… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-70559 Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-70558 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.5 CVE-2026-70557 diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those … No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-67689 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated … No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67688 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke… No fix yet Fix from $2,3002026-08-06 HIGH 8.8 CVE-2026-67687 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleContro… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.9 CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac… No fix yet Fix from $2,3002026-08-06 HIGH 7.6 CVE-2026-67621 Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-64663 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into… No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-63725 sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-con… No fix yet Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-62857 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-61632 PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vul… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.8 CVE-2026-5336 The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes th… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-48076 OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1… No fix yet Fix from $1,6002026-08-06 HIGH 8.6 CVE-2026-47194 Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-45378 Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-documen… No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-43632 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokeni… No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-43631 llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in the vocab pointer of llama-server when the --sleep-idle-se… No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-43629 llama.cpp builds b4882 through b9058 contain a heap buffer overflow vulnerability in the KV cache state restore path where the state_read_data() func… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-43628 llama.cpp builds b3978 through b9058 contain an integer underflow and out-of-bounds read vulnerability in the DRY sampler that allows unauthenticated… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-43627 llama.cpp builds b1283 through b9058 contain an integer overflow vulnerability in the llama_batch_init() function where unchecked multiplications in … No fix yet Fix from $1,9502026-08-06 CRITICAL 9.1 CVE-2026-3418 The System REST API accepts user-supplied file uploads without enforcing sufficient validation on the file type or destination, allowing files to be … No fix yet Fix from $2,3002026-08-06 HIGH 8.7 CVE-2026-3415 The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain condit… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-1289 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force a Use-After-Free vulnerability. A malicious actor can leverage this vul… No fix yet Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-19111 Insecure direct object reference in the mongodb_memory, elasticsearch_memory, and mem0_memory tools in Amazon Strands Agents Tools before 0.8.3 might… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19071 A flaw has been found in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /viewappointment.php. This manipula… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19070 A vulnerability was detected in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewadmin.php. The manipul… No fix yet Fix from $1,6002026-08-06