Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-52199 An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component Mitigation only Fix from $2,3002026-07-17 HIGH 7.5 CVE-2026-51833 Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (… No fix yet Fix from $1,9502026-07-17 HIGH 7.5 CVE-2026-4942 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to send a specifically crafted message and downgrade the Transport Layer Security (TLS) pr… I No fix yet Fix from $1,9502026-07-17 CRITICAL 9.1 CVE-2026-42168 django-pyas2 through 1.2.3 is vulnerable to OS command injection via the cmd_receive and cmd_send fields on the Partner model. These fields are passe… No fix yet Fix from $2,3002026-07-17 CRITICAL 9.8 CVE-2026-36669 An unauthenticated arbitrary file upload vulnerability in ck_upload_handler.php in Feng Office 3.11.13.11 allows remote attackers to upload malicious… No fix yet Fix from $2,3002026-07-17 HIGH 7.1 CVE-2026-16118 A flaw was found in xdgmime. A heap-based buffer overflow can be triggered in _xdg_mime_magic_parse_magic_line() in the xdgmimemagic.c file on little… No fix yet Fix from $1,9502026-07-17 MEDIUM 5.4 CVE-2026-15995 IBM Cognos Analytics 12.1.3 GA Version with build number through 12.1.3-2606251736 could allow an attacker to obtain incorrect report summary results… No fix yet Fix from $1,6002026-07-17 HIGH 7.0 CVE-2026-14971 IBM PowerVM Novalink 2.2.02.2.12.2.1.1, and 2.3.02.3.0.12.3.12.3.2 IBM NovaLink APIs misconfiguration may increase attack surface and enable unintend… Powervm Novalink No fix yet Fix from $1,9502026-07-17 MEDIUM 5.5 CVE-2026-15415 AWS HealthOmics is a HIPAA-eligible service that fully manages the compute, storage, and workflow engine infrastructure required to run bioinformatic… No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-14979 IBM Engineering Lifecycle Management 7.0.3 ( Interim Fix 001 through ) Interim Fix 021, 7.1.0 ( Interim Fix 001 through ) Interim Fix 009, and 7.2.0 … Engineering Lifecycle Management No fix yet Fix from $1,9502026-07-17 MEDIUM 6.8 CVE-2026-12283 Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation… No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2025-51678 An issue was discovered in RISC-V PicoRV32 commit 87c89a. A mismatch in the PCPI INSN and memory address can lead to unexpected behavior. No fix yet Fix from $1,9502026-07-17 CRITICAL 9.1 CVE-2025-51677 An issue was discovered in openRISC OR1200 commit 83ac6b. An output mismatch between the RTL and the netlist of the or1200 cpu output port can lead t… No fix yet Fix from $2,3002026-07-17 HIGH 7.5 CVE-2026-9171 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafte… Powervm Novalink No fix yet Fix from $1,9502026-07-17 HIGH 8.2 CVE-2026-53712 SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authent… No fix yet Fix from $1,9502026-07-17 MEDIUM 6.4 CVE-2026-45703 Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportB… No fix yet Fix from $1,6002026-07-17 HIGH 7.0 CVE-2026-9588 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template fun… No fix yet Fix from $1,9502026-07-17 HIGH 7.1 CVE-2026-9587 An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-co… No fix yet Fix from $1,9502026-07-17 CRITICAL 9.3 CVE-2026-9586 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning… No fix yet Fix from $2,3002026-07-17 HIGH 8.6 CVE-2026-9585 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application f… Mitigation only Fix from $1,9502026-07-17 CRITICAL 9.8 CVE-2026-8297 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laborato… No fix yet Fix from $2,3002026-07-17 MEDIUM 6.5 CVE-2026-63307 Chat2DB before 5.3.0 contains an insecure direct object reference vulnerability in the GET /api/connection/datasource/{id} endpoint. The handler call… No fix yet Fix from $1,6002026-07-17 HIGH 7.5 CVE-2026-63101 Open Event Server through 1.19.1 contains a missing authentication vulnerability that allows unauthenticated attackers to export the complete member … No fix yet Fix from $1,9502026-07-17 CRITICAL 9.3 CVE-2026-54496 ZEBRA is a Zcash node written entirely in Rust. Prior to zebrad 5.0.0, halo2_gadgets 0.5.0, orchard 0.14.0, zcash_primitives 0.28.0, and zcashd 6.20.… No fix yet Fix from $2,3002026-07-17 MEDIUM 5.3 CVE-2026-21762 HCL DevOps Loop is affected by missing HTTP security headers. Missing security headers may reduce browser protections against common web-based attack… Devops Loop No fix yet Fix from $1,6002026-07-17 MEDIUM 5.4 CVE-2026-21761 HCL DevOps Loop is affected by a Cross-Origin Resource Sharing (CORS) misconfiguration. Improper CORS configuration may allow unauthorized cross-orig… Devops Loop No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-16108 A flaw was found in the default-groups REST endpoint and realm representation of Keycloak. This component is responsible for managing groups that are… Build Of Keycloak No fix yet Fix from $1,6002026-07-17 MEDIUM 6.5 CVE-2026-16104 A flaw was found in the authentication configuration endpoint of the keycloak-services component, which is the core engine for Red Hat Build of Keycl… Build Of Keycloak No fix yet Fix from $1,6002026-07-17 MEDIUM 5.4 CVE-2026-16093 Keycloak provides a mechanism called Client Policies to enforce security requirements on clients, such as requiring them to use signed JWTs for authe… Build Of Keycloak No fix yet Fix from $1,6002026-07-17 CRITICAL 9.1 CVE-2026-12694 Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This… No fix yet Fix from $2,3002026-07-17