Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-63913 An issue was discovered in OpenSBI 1.3 allowing attackers to cause a denial of service via crafted request to the SBI function #2 or the 'Find and co… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-51078 An issue in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the str parameter of the file_manage_control.php component No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-51077 SQL injection vulnerability in Dede CMS v.5.7.118 allows a remote attacker to obtain sensitive information via the sqlquery parameter of the sys_sql_… No fix yet Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2021-32088 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. Certain API endpoints contain a rate-limiting feature to minimize … Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 HIGH 8.8 CVE-2021-32087 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The kbftp account has a… Kace Systems Management Appliance Mitigation only Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2021-32086 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It uses a hardcoded symmetric encryption key to encrypt secrets in… Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 HIGH 8.8 CVE-2021-32085 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. It installs with default user credentials. The report and R1 MySQL… Kace Systems Management Appliance No fix yet Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2021-32084 An issue was discovered in Quest KACE Systems Deployment Appliance (SMA) 11.0.273. If a customer restricts access to the web console by IP address or… Kace Systems Management Appliance No fix yet Fix from $2,3002026-07-27 HIGH 8.8 CVE-2026-64555 In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix SPSR_EL2 restore in kvm_hyp_handle_mops() kvm_hyp_handle_mo… No fix yet Fix from $1,9502026-07-27 HIGH 8.8 CVE-2026-64554 In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: fix stale prevhdr pointer in br_ip6_fragment() br_ip6_fragme… Mitigation only Fix from $1,9502026-07-27 HIGH 8.4 CVE-2026-64552 In the Linux kernel, the following vulnerability has been resolved: virtio-net: fix len check in receive_big() receive_big() bounds the device-anno… No fix yet Fix from $1,9502026-07-27 CRITICAL 9.1 CVE-2026-64551 In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR… No fix yet Fix from $2,3002026-07-27 HIGH 7.3 CVE-2026-64550 In the Linux kernel, the following vulnerability has been resolved: net: qualcomm: rmnet: validate MAP frame length before ingress parsing When ing… No fix yet Fix from $1,9502026-07-27 HIGH 8.4 CVE-2026-64548 In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: reject overflowing copy + len in bpf_msg_push_data() When the sca… No fix yet Fix from $1,9502026-07-27 HIGH 8.1 CVE-2026-64547 In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For a… No fix yet Fix from $1,9502026-07-27 HIGH 7.1 CVE-2026-64546 In the Linux kernel, the following vulnerability has been resolved: drm/edid: fix OOB read in drm_parse_tiled_block() drm_parse_tiled_block() casts… No fix yet Fix from $1,9502026-07-27 HIGH 7.5 CVE-2026-64545 In the Linux kernel, the following vulnerability has been resolved: net, bpf: check master for NULL in xdp_master_redirect() xdp_master_redirect() … No fix yet Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-64543 In the Linux kernel, the following vulnerability has been resolved: tipc: fix use-after-free of the discoverer in tipc_disc_rcv() bearer_disable() … No fix yet Fix from $1,9502026-07-27 CRITICAL 9.8 CVE-2026-64541 In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handl… No fix yet Fix from $2,3002026-07-27 HIGH 8.1 CVE-2026-64540 In the Linux kernel, the following vulnerability has been resolved: usbnet: gl620a: fix out-of-bounds read in genelink_rx_fixup() genelink_rx_fixup… No fix yet Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-64539 In the Linux kernel, the following vulnerability has been resolved: Bluetooth: eir: Fix stack OOB write when prepending the Flags AD eir_create_adv… No fix yet Fix from $1,9502026-07-27 MEDIUM 5.2 CVE-2026-12001 A hardcoded credential vulnerability exists in the firmware of multiple TP-Link routers (TL-WR845N v4, TL-WR850N v3, TL-WR902AC v4, Archer C20 v6 & A… No fix yet Fix from $1,6002026-07-27 HIGH 7.1 CVE-2026-66759 A flaw was found in the file-icns plugin in GIMP. When applying a decompressed mask during ICNS image processing, the plugin reads from the mask data… Enterprise Linux No fix yet Fix from $1,9502026-07-27 HIGH 7.8 CVE-2026-66758 A flaw was found in the file-fits plugin in GIMP. When processing a FITS image file, the plugin calculates memory allocation sizes using signed 32-bi… Enterprise Linux No fix yet Fix from $1,9502026-07-27 MEDIUM 5.5 CVE-2026-66757 A flaw was found in the file-sgi plugin in GIMP. When processing an RLE-compressed SGI image, the plugin allocates memory for a row table. The image … Enterprise Linux No fix yet Fix from $1,6002026-07-27 MEDIUM 5.4 CVE-2026-66031 Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject… No fix yet Fix from $1,6002026-07-27 HIGH 7.5 CVE-2026-51244 schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in UnpackFrameHeader(). Multiple attacker-controlled index parameters are used … No fix yet Fix from $1,9502026-07-27 MEDIUM 6.9 CVE-2026-17612 Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to and including version HC5.26.1.14.20260207 contains an audit log disclosure Vuln… No fix yet Fix from $1,6002026-07-27 HIGH 7.5 CVE-2026-12383 A flaw was found in the Event-Driven Ansible (EDA) server. The ExternalEventStreamViewSet uses permissive access controls (permission_classes=[AllowA… No fix yet Fix from $1,9502026-07-27 MEDIUM 5.4 CVE-2026-66030 Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to injec… No fix yet Fix from $1,6002026-07-27