Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-12382 A flaw was found in the AAP Gateway Envoy proxy configuration. The non-mTLS route to EDA event streams does not remove the Subject HTTP header from c… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.5 CVE-2026-9007 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected … Mitigation only Fix from $1,6002026-07-15 HIGH 8.8 CVE-2026-55242 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, an authenticated user with a standard operational… Mitigation only Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-45806 Penpot is an open-source design tool for design and code collaboration. Prior to 2.15.0, Penpot's remote image import passed the user-controlled url … Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.3 CVE-2026-45150 Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage ent… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.3 CVE-2026-61646 FastGPT is a knowledge-based AI application platform. Prior to 4.15.0-beta5, FastGPT's shared SSRF guard validates only the initial request URL befor… Mitigation only Fix from $1,6002026-07-15 HIGH 7.7 CVE-2026-61613 Cursor is a code editor built for programming with AI. Prior to the Cloud Agent fix on 03/31/2026, browser-enabled Cursor Cloud Agent sessions allowe… Mitigation only Fix from $1,9502026-07-15 HIGH 7.1 CVE-2026-54563 Cloudreve is a self-hosted file management and sharing system. Prior to 4.16.1, a Cloudreve WebDAV account rooted at a configured folder can send pat… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.5 CVE-2026-58559 DoS vulnerability in the vibration service. Impact: Successful exploitation of this vulnerability may affect availability. No fix yet Fix from $1,6002026-07-15 HIGH 7.8 CVE-2026-58558 Permission control vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect service confidentiality. No fix yet Fix from $1,9502026-07-15 MEDIUM 5.1 CVE-2026-58556 Permission control vulnerability in the Bluetooth module. Impact: Successful exploitation of this vulnerability may affect availability. No fix yet Fix from $1,6002026-07-15 MEDIUM 6.6 CVE-2026-58555 Permission bypass vulnerability in the card module. Impact: Successful exploitation of this vulnerability may affect availability. No fix yet Fix from $1,6002026-07-15 MEDIUM 6.6 CVE-2026-58554 Permission control vulnerability in the Settings module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. No fix yet Fix from $1,6002026-07-15 MEDIUM 5.1 CVE-2026-58552 Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. No fix yet Fix from $1,6002026-07-15 MEDIUM 5.1 CVE-2026-58551 Out-of-bounds read vulnerability in the image codec module. Impact: Successful exploitation of this vulnerability may affect service confidentiality. No fix yet Fix from $1,6002026-07-15 MEDIUM 5.3 CVE-2026-46459 ICU Scandinavia Boomerang is vulnerable to a missing authentication flaw in its device receiver endpoints. This allows an unauthenticated remote atta… Mitigation only Fix from $1,6002026-07-15 HIGH 7.1 CVE-2026-46458 ICU Scandinavia Boomerang is vulnerable to an information disclosure flaw where sensitive credential files are exposed via static HTTP. This allows a… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.1 CVE-2026-15779 A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the pat… Mitigation only Fix from $1,6002026-07-15 HIGH 8.1 CVE-2026-61873 Grav before 9.1.8 contains an arbitrary file write vulnerability in the Form plugin's process.save.filename parameter, which is validated against pat… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-61457 The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 contains a file upload extension bypass in the API media controller. HandlesMediaUploads::… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.1 CVE-2026-61453 Grav v2.0.0 contains a cross-site scripting vulnerability (fixed in 2.0.1). The XSS blueprint validator (Security::detectXss()) runs on raw page cont… Mitigation only Fix from $1,6002026-07-15 MEDIUM 5.3 CVE-2026-61452 The Grav API plugin (getgrav/grav-plugin-api) before 2.0.4 contains an improper session invalidation vulnerability where JWT access tokens are issued… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.6 CVE-2026-61451 The Grav API plugin (grav-plugin-api) before 1.0.4 does not validate the origin of the client-supplied admin_base_url field in the POST /api/v1/auth/… Mitigation only Fix from $2,3002026-07-15 MEDIUM 6.5 CVE-2026-61449 Grav 2.0.1 contains a decompression-bomb size-cap bypass in ZipArchiver and GPM\Installer. The size bound introduced in 2.0.1 sums the uncompressed s… No fix yet Fix from $1,6002026-07-15 HIGH 8.4 CVE-2026-61446 PraisonAI (praisonaiagents) before 1.6.78 contains a remote code execution vulnerability in the plugin manager, which loads and executes arbitrary Py… Mitigation only Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-61443 PraisonAI before 1.6.78 contains a remote code execution vulnerability in SkillTools.run_skill_script() that executes scripts without path containmen… Mitigation only Fix from $1,9502026-07-15 HIGH 7.3 CVE-2026-61438 PraisonAI before 4.6.78 contains a remote code execution vulnerability in JobWorkflowExecutor._exec_inline_python() due to insufficient AST validatio… Mitigation only Fix from $1,9502026-07-15 HIGH 8.5 CVE-2026-61430 PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostnames at check time but re-reso… Mitigation only Fix from $1,9502026-07-15 HIGH 7.3 CVE-2026-61427 PraisonAI before 4.6.78 exposes the MCP HTTP-stream transport without authentication by default: the CLI --api-key option defaults to None, and the s… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.1 CVE-2026-60087 PraisonAI before 1.6.78 caches tool approval decisions by tool name only, allowing attackers to reuse initial approvals for subsequent calls with arb… Mitigation only Fix from $1,6002026-07-15