Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-36162 An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbi… Mitigation only Fix from $1,6002026-07-07 CRITICAL 9.8 CVE-2026-37271 Fire-Boltt Smartwatch FB BGS001 Firmware: MOY-JS14-2.0.4 is vulnerable to Improper Authentication, The device accepts GATT Write Request commands wit… Mitigation only Fix from $2,3002026-07-07 CRITICAL 9.8 CVE-2026-37270 Trueview Security camera T18161- AF v4.9.60.0 contains an authentication bypass vulnerability caused by improper password validation and the presence… Mitigation only Fix from $2,3002026-07-07 HIGH 8.4 CVE-2026-55408 Koodo Reader is an ebook reader. In version 2.3.0 and earlier, Koodo Reader is vulnerable to remote code execution through malicious EPUB files becau… Mitigation only Fix from $1,9502026-07-07 HIGH 7.8 CVE-2026-49033 The application contains a stack-based buffer overflow vulnerability that can be exploited by an attacker to execute arbitrary code. Mitigation only Fix from $1,9502026-07-07 HIGH 7.8 CVE-2026-42958 The application contains a use-after-free vulnerability that can be exploited to cause memory corruption while parsing specially crafted files. This … Mitigation only Fix from $1,9502026-07-07 HIGH 8.4 CVE-2026-42953 The application contains an out-of-bounds write vulnerability that can be exploited by an attacker to cause the program to write data past the end of… No fix yet Fix from $1,9502026-07-07 HIGH 7.1 CVE-2026-58583 FluxInk (formerly Sunia SPB Peripheral) Color Management Driver (TcnPeripheral64.sys) 1.0.7.2 allows local privilege escalation for a standard user a… Mitigation only Fix from $1,9502026-07-07 MEDIUM 6.9 CVE-2026-55417 Chevereto is a self-hosted media-sharing platform. Starting in version 3.7.5 and prior to version 4.5.4, when a user enables the private profile opti… Mitigation only Fix from $1,6002026-07-07 MEDIUM 6.5 CVE-2026-44877 An unauthenticated remote disclosure vulnerability has been identified in HPE Networking Instant On 1830, 1930, and 1960 Switches. Successful exploit… Mitigation only Fix from $1,6002026-07-07 CRITICAL 9.8 CVE-2026-59800 9Router before 0.4.44 contains an OS command injection vulnerability in the unauthenticated POST /api/tunnel/tailscale-install endpoint (this route i… Mitigation only Fix from $2,3002026-07-07 HIGH 7.8 CVE-2026-57851 MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user… Mitigation only Fix from $1,9502026-07-07 HIGH 7.2 CVE-2026-23698 Vtiger CRM through 8.4.0 contains an authenticated remote code execution vulnerability in the admin module import feature that allows administrator-l… Mitigation only Fix from $1,9502026-07-07 MEDIUM 6.5 CVE-2026-14904 AWS Research and Engineering Studio (RES) is an open-source solution that enables researchers and engineers to create and manage secure virtual deskt… Mitigation only Fix from $1,6002026-07-07 HIGH 8.8 CVE-2026-23697 Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uplo… Mitigation only Fix from $1,9502026-07-07 MEDIUM 6.5 CVE-2025-12799 A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped ch… Mitigation only Fix from $1,6002026-07-07 MEDIUM 5.3 CVE-2026-14940 A heap-buffer-overflow flaw was found in 389 Directory Server (389-ds-base). When normalizing a Distinguished Name (DN) that contains a legacy-quoted… Directory Server Mitigation only Fix from $1,6002026-07-07 MEDIUM 5.9 CVE-2026-12352 This vulnerability allows an unauthenticated actor to bypass authentication and gain access to restricted resources on the device. Mitigation only Fix from $1,6002026-07-07 HIGH 7.5 CVE-2026-6101 The AMP for WP – Accelerated Mobile Pages plugin for WordPress is vulnerable to Arbitrary File Write in versions up to and including 1.1.12. This is … Mitigation only Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-44938 A vulnerability has been identified in Fleet's agent-side deployer, which did not filter security-sensitive keys from namespaceLabels in fleet.yaml (… Mitigation only Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-13696 Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in HAVELSAN Inc. Liman MYS allows LDAP Injection. … Mitigation only Fix from $1,9502026-07-07 HIGH 8.1 CVE-2026-11348 Improper verification of cryptographic signature vulnerability in HAVELSAN Inc. Liman MYS allows Fake the Source of Data. This issue affects Liman M… Mitigation only Fix from $1,9502026-07-07 CRITICAL 9.8 CVE-2011-10043 Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to … Mitigation only Fix from $2,3002026-07-07 HIGH 8.3 CVE-2026-11340 Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects L… Mitigation only Fix from $1,9502026-07-07 HIGH 8.0 CVE-2026-14476 A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFile… Mitigation only Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-14474 A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP dire… Mitigation only Fix from $1,9502026-07-07 HIGH 8.8 CVE-2026-11610 A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protec… Mitigation only Fix from $1,9502026-07-07 HIGH 7.8 CVE-2026-58384 A flaw was found in GIMP's PSD parser. An integer overflow in read_RLE_channel() can cause an undersized heap allocation for the RLE row-length table… Enterprise Linux Mitigation only Fix from $1,9502026-07-07 MEDIUM 5.4 CVE-2026-8309 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access… Mitigation only Fix from $1,6002026-07-07 HIGH 8.2 CVE-2026-8377 Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource … Mitigation only Fix from $1,9502026-07-07