Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2026-20475 In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious ac… Mt8910 Firmware No fix yet Fix from $1,6002026-08-03 MEDIUM 6.0 CVE-2026-20474 In display, there is a possible escalation of privilege due to a race condition. This could lead to local escalation of privilege if a malicious acto… Mt6991 Firmware No fix yet Fix from $1,6002026-08-03 MEDIUM 6.0 CVE-2026-20473 In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor has al… Mt6991 Firmware No fix yet Fix from $1,6002026-08-03 MEDIUM 6.2 CVE-2026-20470 In Telephony, there is a possible information disclosure due to a missing permission check. This could lead to local information disclosure with no a… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.0 CVE-2026-20469 In trusted_mem, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege if a m… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.0 CVE-2026-20468 In apusys, there is a possible escalation of privilege due to a confused deputy. This could lead to local escalation of privilege if a malicious acto… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.0 CVE-2026-20467 In apusys, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-20466 In sec boot, there is a possible escalation of privilege due to a heap buffer overflow. This could lead to local escalation of privilege, if an attac… No fix yet Fix from $1,6002026-08-03 HIGH 8.1 CVE-2026-20465 In wlan AP driver, there is a possible out of bounds write due to a missing bounds check. This could lead to remote (proximal/adjacent) escalation of… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-20464 In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalation of privilege if a malicious… No fix yet Fix from $1,6002026-08-03 HIGH 7.1 CVE-2026-65875 BaserCMS provided by baserCMS Users Community contains a CSV file injection vulnerability. If a user downloads and opens a CSV file containing malici… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-3245 A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. No fix yet Fix from $1,9502026-08-03 MEDIUM 5.4 CVE-2026-68583 luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-68582 Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1… No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-68580 FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL … No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-68578 ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently … No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-67357 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluste… No fix yet Fix from $1,9502026-08-02 HIGH 8.8 CVE-2026-67356 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe… No fix yet Fix from $1,9502026-08-02 MEDIUM 5.9 CVE-2025-71401 better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An … No fix yet Fix from $1,6002026-08-02 HIGH 7.1 CVE-2025-71400 better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth… No fix yet Fix from $1,9502026-08-02 MEDIUM 6.4 CVE-2026-12231 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-18573 A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs … Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-18572 Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 HIGH 7.2 CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi… Build Of Keycloak No fix yet Fix from $1,9502026-08-02 MEDIUM 5.4 CVE-2026-18570 A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This component is responsible for enforcin… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 5.4 CVE-2026-16292 The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing… No fix yet Fix from $1,6002026-08-02 HIGH 7.5 CVE-2026-16540 The Simply Schedule Appointments WordPress plugin before 1.6.12.6 does not correctly restrict a bulk appointment operation to the requester's own rec… No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-16285 The Product Attachment for WooCommerce WordPress plugin before 2.3.3 does not perform any authorization check before streaming media library files, a… No fix yet Fix from $1,9502026-08-02 CRITICAL 9.8 CVE-2026-16256 The POUCO Import Users WordPress plugin through 1.0.0 does not perform any capability or nonce checks on AJAX actions available to unauthenticated us… No fix yet Fix from $2,3002026-08-02 HIGH 7.5 CVE-2026-16261 The login-social WordPress plugin through 1.0.4 does not validate password-reset requests against a reset key or the requester's identity, and it iss… No fix yet Fix from $1,9502026-08-02