Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-44752 SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses … Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.9 CVE-2026-44747 SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption t… Mitigation only Fix from $2,3002026-07-14 HIGH 8.1 CVE-2026-44745 SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthent… Mitigation only Fix from $1,9502026-07-14 CRITICAL 9.1 CVE-2026-27690 Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads t… Mitigation only Fix from $2,3002026-07-14 MEDIUM 5.3 CVE-2026-15621 A vulnerability was detected in mosaxiv clawlet up to 0.2.10. This impacts the function read_file/write_file/edit_file of the file tools/fs_ops.go of… No fix yet Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15620 A security vulnerability has been detected in mosaxiv clawlet up to 0.2.10. This affects the function tools.webFetch of the file tools/tool_web_fetch… Mitigation only Fix from $1,6002026-07-14 HIGH 8.4 CVE-2026-0487 SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute ma… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.3 CVE-2026-15619 A weakness has been identified in mosaxiv clawlet up to 0.2.10. The impacted element is the function web_fetch of the file tools/tool_web_fetch.go of… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15618 A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. The affected element is the function guardExecCommand of the file tools/tool_exe… Mitigation only Fix from $1,6002026-07-14 HIGH 7.5 CVE-2026-62328 9Router through version 0.4.41 contain an unauthenticated information disclosure vulnerability that allows remote attackers to access sensitive user … Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.1 CVE-2026-62327 9Router through version 0.4.41 contains an unauthenticated information disclosure vulnerability that allows remote attackers to retrieve plaintext AP… Mitigation only Fix from $2,3002026-07-13 HIGH 7.6 CVE-2026-62185 Argo CD Helm Chart before 10.0.0 fails to install network policies by default, allowing any pod on a cluster to access repo-server and other Argo API… Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-61458 PasswordPusher before 2.9.2 contains a brute-force vulnerability in the POST /p/:token/access endpoint that lacks route-specific rate limiting and pe… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.8 CVE-2026-52533 An issue in D-Link DIR-1253 v.1.0.1.250923.142435 allows an attacker to escalate privileges via the etc/shadow component file No fix yet Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-59801 9Router through version 0.4.41 contains an unauthenticated access vulnerability that allows remote attackers to interact with provider management API… Mitigation only Fix from $2,3002026-07-13 MEDIUM 6.9 CVE-2026-58488 HedgeDoc is an open source, real-time, collaborative, markdown notes application. Versions prior to 1.11.0 allowed attackers to circumvent the rate-l… Mitigation only Fix from $1,6002026-07-13 MEDIUM 5.1 CVE-2026-58487 HedgeDoc is an open source, real-time, collaborative, markdown notes application. Prior to version 1.11.0, due to unsafe handling of the local-part o… Mitigation only Fix from $1,6002026-07-13 HIGH 7.0 CVE-2026-58411 ChurchCRM is an open-source church management system. Prior to version 7.4.0, Cross-Site Scripting (XSS) vulnerabilities were identified due to insuf… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-56877 The SCORM lab launch endpoint in Skillable (scorm.skillable.com) through 2026-07-13 does not validate the client-supplied userId parameter against th… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.8 CVE-2026-51821 SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUser… Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51541 OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in CIP message parsing when handling malformed explicit requests with a forged EPath si… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.8 CVE-2026-51540 OpENer 2.3.0 (master branch up to commit 76b95cf) is vulnerable to a severe memory corruption issue caused by an integer underflow in the processing … Opener Mitigation only Fix from $2,3002026-07-13 HIGH 7.5 CVE-2026-51539 A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.1 CVE-2026-51538 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) suffers from an Incorrect Access Control vulnerability in its handling of encapsulation sessions. When th… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51537 EIPStackGroup OpENer 2.3.0 (commit 76b95cf) has an out-of-bounds read issue in Connection Manager handling of ForwardOpen requests when processing sh… Opener Mitigation only Fix from $2,3002026-07-13 CRITICAL 9.1 CVE-2026-51536 In OpENer 2.3.0 (commit 76b95cf) when parsing incoming CIP (Common Industrial Protocol) network packets, the length parameter is inconsistently typed… Opener Mitigation only Fix from $2,3002026-07-13 HIGH 7.5 CVE-2026-39042 An issue in MikroTIk (SIA Mikrotikls, Latvia) RouterOS 7.21.x before v.7.21.4 and 7.22.x before v.7.22.2 allows a remote attacker to cause a denial o… Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-15685 Ollama downloadBlob Improper Validation of Array Index Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial… Ollama Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.5 CVE-2026-15682 AnyDesk Support Information Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service c… Anydesk Mitigation only Fix from $1,6002026-07-13 MEDIUM 5.5 CVE-2026-15681 AnyDesk Screen Recording Link Following Denial-of-Service Vulnerability. This vulnerability allows local attackers to create a denial-of-service cond… Anydesk Mitigation only Fix from $1,6002026-07-13