Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-67858 Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the M… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67856 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(S… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67855 open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This all… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.1 CVE-2026-52370 A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in th… No fix yet Fix from $1,6002026-08-04 MEDIUM 6.1 CVE-2026-51144 Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-67857 open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. No fix yet Fix from $1,9502026-08-04 HIGH 8.7 CVE-2026-45084 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the … No fix yet Fix from $1,9502026-08-04 MEDIUM 5.0 CVE-2026-18816 A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_… No fix yet Fix from $1,6002026-08-04 HIGH 7.2 CVE-2026-18814 A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in com… No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-70554 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.1 CVE-2026-67979 Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary … Mitigation only Fix from $2,3002026-08-04 MEDIUM 6.3 CVE-2026-70490 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backen… No fix yet Fix from $1,6002026-08-04 HIGH 7.7 CVE-2026-51401 An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/sr… No fix yet Fix from $1,9502026-08-04 HIGH 8.4 CVE-2026-51400 An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/sr… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.3 CVE-2026-54020 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL vali… No fix yet Fix from $1,6002026-08-04 CRITICAL 9.8 CVE-2026-45538 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longe… No fix yet Fix from $2,3002026-08-04 HIGH 7.2 CVE-2026-18813 A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.ap… No fix yet Fix from $1,9502026-08-04 HIGH 7.2 CVE-2026-18812 A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the… No fix yet Fix from $1,9502026-08-04 HIGH 7.2 CVE-2026-18811 A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the a… No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-13227 An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API … No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-70553 MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application co… No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-70552 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access … No fix yet Fix from $2,3002026-08-04 CRITICAL 9.2 CVE-2026-70478 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:… No fix yet Fix from $2,3002026-08-04 HIGH 7.3 CVE-2026-18810 A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulat… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-16793 An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) … No fix yet Fix from $1,9502026-08-04 MEDIUM 6.1 CVE-2026-16792 An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an… No fix yet Fix from $1,6002026-08-04 HIGH 7.6 CVE-2026-70474 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credenti… No fix yet Fix from $1,9502026-08-04 HIGH 7.1 CVE-2026-70471 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the co… No fix yet Fix from $1,9502026-08-04 MEDIUM 6.5 CVE-2026-69704 Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET pa… No fix yet Fix from $1,6002026-08-04 CRITICAL 9.8 CVE-2026-69703 Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated att… Mitigation only Fix from $2,3002026-08-04