Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-57896 An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.8 CVE-2026-38158 A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform… No fix yet Fix from $2,3002026-07-16 MEDIUM 6.5 CVE-2026-36425 An issue in OPSWAT AppRemover Driver (ardrv.sys) v2017.10.02.1551 and earlier in IOCTL handler 0x2420031. Any local user can open the device and send… No fix yet Fix from $1,6002026-07-16 HIGH 8.1 CVE-2026-44019 Docling Core defines core data types and transformations for the document processing application Docling. In versions 2.5.0 and above, prior to 2.74.… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-11889 SALTO ProAccess Space software using the tenancy feature / logical partition is vulnerable to a privilege escalation attack that could allow an aut… No fix yet Fix from $1,6002026-07-16 HIGH 7.1 CVE-2024-34268 EQ-3 Eqiva CC-RT-BLE Bluetooth Smart Radiator Thermostat Firmware up to the latest version 1.46 was discovered to allow unsecured bluetooth connectio… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.7 CVE-2024-32387 An issue in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive information via the communi… No fix yet Fix from $1,6002026-07-16 HIGH 7.3 CVE-2024-32386 Directory traversal vulnerability in Kerlink Kerlink Wirnet iStation 868 KerOS v.4.3.3_20200803132042 allows a remote attacker to obtain sensitive in… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.4 CVE-2026-63397 remorses/genql before version 6.3.4 allows an authenticated attacker with control of the GraphQL schema that is passed to genql to inject arbitrary J… No fix yet Fix from $1,6002026-07-16 HIGH 7.0 CVE-2026-61389 An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL requ… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.1 CVE-2026-60140 An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT… No fix yet Fix from $1,6002026-07-16 HIGH 7.0 CVE-2026-60063 An out-of-bounds write vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption via a crafted IOCTL requ… No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-15352 A vulnerability exists in the Health & Safety (HS) application of NASA's Core Flight System (cFS). The flaw allows the application to crash via segme… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.5 CVE-2026-47084 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-47082 An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacat… No fix yet Fix from $1,6002026-07-16 HIGH 7.7 CVE-2026-46687 Emlog is an open source website building system. In 2.6.13 and earlier, the article publishing interface stores a path-traversal template parameter f… No fix yet Fix from $1,9502026-07-16 HIGH 8.5 CVE-2026-46686 Emlog is an open source website building system. In 2.6.13 and earlier, the admin backend user search module's keyword parameter from admin/user.php … No fix yet Fix from $1,9502026-07-16 CRITICAL 10.0 CVE-2026-45336 HireFlow is a web-based interview management system for managing candidates, scheduling interviews, and tracking hiring progress. In 1.2 and earlier,… No fix yet Fix from $2,3002026-07-16 MEDIUM 5.7 CVE-2026-15737 AWS Bedrock AgentCore Python SDK is an open-source Python library that provides client tools for building AI agents on the Amazon Bedrock AgentCore p… No fix yet Fix from $1,6002026-07-16 HIGH 7.0 CVE-2026-9046 A potential insecure permissions vulnerability was reported in Legion Zone and the Lenovo App Store Windows applications, distributed exclusively in … No fix yet Fix from $1,9502026-07-16 MEDIUM 5.5 CVE-2026-6511 During an internal security assessment, a potential improper access control vulnerability was discovered in Lenovo Smart Connect for Windows that cou… No fix yet Fix from $1,6002026-07-16 HIGH 8.6 CVE-2026-63088 stoatchat before 0.14.0 contains a server-side request forgery (SSRF) vulnerability that allows unauthenticated network-accessible attackers to bypas… No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-63087 Grafana OnCall through 1.16.11 contains an unauthenticated access vulnerability that allows remote attackers to obtain a valid PluginAuthToken by sen… No fix yet Fix from $2,3002026-07-16 HIGH 8.6 CVE-2026-63086 text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compatible multimodal chat completi… No fix yet Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-63085 Axelor Open Platform versions 8.x prior to 8.2.2 contains an authorization bypass vulnerability that allows authenticated non-admin users to escalate… No fix yet Fix from $1,9502026-07-16 CRITICAL 9.8 CVE-2026-3031 Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library. Image::EPEG includes Epeg 0.9.0 that was last updated … No fix yet Fix from $2,3002026-07-16 HIGH 8.8 CVE-2026-14371 The Lenovo XClarity Integrator for Windows Admin Center plugin version 5.1.1 and below running on the WAC Gateway is vulnerable to Powershell Command… No fix yet Fix from $1,9502026-07-16 HIGH 7.3 CVE-2026-13104 A potential vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local authenticated use… No fix yet Fix from $1,9502026-07-16 HIGH 7.3 CVE-2026-13103 A potential path traversal vulnerability was reported in Lenovo App Store, distributed exclusively in the Chinese market, that could allow a local au… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.0 CVE-2026-10589 A potential out of bounds write vulnerability could allow a local privileged attacker to execute code in System Management Mode. No fix yet Fix from $1,6002026-07-16