Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-66374 Knot Resolver before 6.4.1 allows remote code execution via a heap-based buffer overflow in the DoQ (DNS-over-QUIC) receive path. No fix yet Fix from $1,9502026-07-25 MEDIUM 6.5 CVE-2026-66339 A flaw was found in libsoup. After a CONNECT tunnel is established through an HTTP proxy, libsoup incorrectly attaches the Proxy-Authorization header… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.4 CVE-2026-66338 A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes that silently accepts inputs vio… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-66337 A flaw was found in libsoup. An unsigned integer underflow in the soup_filter_input_stream_read_until() function causes a heap buffer over-read when … No fix yet Fix from $1,6002026-07-24 HIGH 8.8 CVE-2026-61892 Weintek cMT3092X HMI allows a non-privileged user to modify tokens to escalate privileges. No fix yet Fix from $1,9502026-07-24 MEDIUM 6.5 CVE-2026-61886 Weintek cMT3092X HMI stores user account passwords in plaintext. No fix yet Fix from $1,6002026-07-24 MEDIUM 6.5 CVE-2026-60135 An attacker can modify data that should be restricted to read‑only access. No fix yet Fix from $1,6002026-07-24 HIGH 8.8 CVE-2026-60134 Weintek cMT3092X HMI allows a non-privileged user to modify cookies to gain elevated privileges. No fix yet Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-61884 The web management interface of Tycon Systems TPDIN-Monitor-WEB2  does not perform server-side validation of credentials during the login process. B… No fix yet Fix from $2,3002026-07-24 HIGH 7.5 CVE-2026-62835 Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network. Azure Portal No fix yet Fix from $1,9502026-07-24 HIGH 8.1 CVE-2026-54342 In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p… No fix yet Fix from $1,9502026-07-24 CRITICAL 9.1 CVE-2026-48021 In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha… No fix yet Fix from $2,3002026-07-24 HIGH 8.5 CVE-2026-17107 A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-eng… No fix yet Fix from $1,9502026-07-24 HIGH 7.2 CVE-2026-65711 sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands … No fix yet Fix from $1,9502026-07-24 HIGH 7.1 CVE-2026-65710 sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag… No fix yet Fix from $1,9502026-07-24 HIGH 8.3 CVE-2026-65709 sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume… No fix yet Fix from $1,9502026-07-24 HIGH 8.1 CVE-2026-65708 sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.5 CVE-2026-65707 Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by … No fix yet Fix from $1,6002026-07-24 HIGH 7.2 CVE-2026-65693 Microweber CMS through 2.0.20 contains a server-side template injection vulnerability that allows authenticated administrators to achieve arbitrary O… No fix yet Fix from $1,9502026-07-24 HIGH 8.1 CVE-2026-8789 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce ver… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.1 CVE-2026-8308 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Polen Media Software and Information Services W… No fix yet Fix from $1,6002026-07-24 CRITICAL 9.8 CVE-2026-58630 Improper access control in Azure App Service allows an unauthorized attacker to elevate privileges over a network. Azure App Service For Linux No fix yet Fix from $2,3002026-07-24 CRITICAL 9.8 CVE-2026-58586 Image::WebP versions before 0.3.0 for Perl bundle a vulnerable version of libwebp. Image::WebP does not link to the system libwebp. Instead, it uses… No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-57106 Server-side request forgery (ssrf) in Data Quality allows an unauthorized attacker to elevate privileges over a network. Purview Data Governance No fix yet Fix from $2,3002026-07-24 CRITICAL 10.0 CVE-2026-56163 Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo… Azure Kubernetes Service No fix yet Fix from $2,3002026-07-24 HIGH 8.7 CVE-2026-55732 Out-of-bounds Read (CWE-125) in BACnet packet parsing (`bacdt_datetime_to_tod`) in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and … No fix yet Fix from $1,9502026-07-24 MEDIUM 6.6 CVE-2026-55731 Unchecked input for loop condition (CWE-606) in the SNMP agent in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4… No fix yet Fix from $1,6002026-07-24 HIGH 8.7 CVE-2026-55730 Reflected Cross-Site Scripting (CWE-79) in LWEB802 in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthenticated remote attacker to exec… No fix yet Fix from $1,9502026-07-24 HIGH 7.7 CVE-2026-55729 Exposure of Sensitive Information (CWE-200) in LWEB802 browser `localStorage` in Loytec LWEB-802 before 5.0.8 on all platforms allows an unauthentica… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.5 CVE-2026-17059 A flaw was found in the role-users endpoint of the keycloak-services library, which is the core component of the Keycloak identity and access managem… Build Of Keycloak No fix yet Fix from $1,6002026-07-24