Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-20461 In Modem, there is a possible out of bounds write due to a missing bounds check. This could lead to remote denial of service, if a UE has connected t… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-20460 In Modem, there is a possible information disclosure due to improper input validation. This could lead to remote information disclosure, if a UE has … Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-20459 In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a … Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-20458 In Modem, there is a possible memory corruption due to a missing bounds check. This could lead to remote escalation of privilege, if a UE has connect… Mitigation only Fix from $1,9502026-07-01 MEDIUM 5.3 CVE-2026-20457 In Modem, there is a possible system crash due to improper input validation. This could lead to remote denial of service, if a UE has connected to a … Mitigation only Fix from $1,6002026-07-01 HIGH 7.8 CVE-2026-14191 An out-of-bounds heap write exists in the RAR5 recovery-volume (.rev) parser in WinRAR and UnRAR (RecVolumes5::ReadHeader in recvol5.cpp). The RecIte… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.3 CVE-2026-54903 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.load is vulnerable to heap corrupt… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.3 CVE-2026-54902 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, is vulnerable to Use-After-Free when in S… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.3 CVE-2026-54901 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj::Parser in usual mode does not mar… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.3 CVE-2026-54900 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, when in usual mode with create_id ena… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.3 CVE-2026-54899 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. Prior to version 3.17.2, disabling symbol_keys on a reused Oj::Par… Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-54592 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj::Doc#each_child, when invoked recu… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.3 CVE-2026-54502 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.2, Oj.dump is vulnerable to a stack-base… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-54500 Oj (Optimized JSON) is a JSON parser and Object marshaller packaged as a Ruby gem. In versions prior to 3.17.3, Oj.load in :object mode reads uniniti… Mitigation only Fix from $1,6002026-07-01 HIGH 8.8 CVE-2026-57995 phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in GroupController::updatePermissions that allows GROUP_EDIT administrators to gr… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-56700 Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca… Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-56415 Storage Concentrator (SC & SCVM) contains a command injection vulnerability within the debug.pl script that is reachable without authentication. A re… Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-56413 Storage Concentrator (SC & SCVM) contains a command injection vulnerability in the ms_service.pl service, which listens on TCP port 9000 by default a… Mitigation only Fix from $2,3002026-06-30 MEDIUM 5.3 CVE-2026-56331 Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 instead of safe 4xx errors wh… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-56328 Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unnamed /updates requests withou… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.3 CVE-2026-56327 Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function that allows unauthenticated atta… Mitigation only Fix from $1,6002026-06-30 HIGH 7.1 CVE-2026-56320 Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_id parameter without validatin… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.3 CVE-2026-56318 Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endpoint that returns different e… Mitigation only Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-56300 Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey that expose API key validity or… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2026-56286 Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows deletion without password re-authe… Mitigation only Fix from $1,9502026-06-30 HIGH 7.6 CVE-2026-56249 Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authenticated users to overwrite ex… Mitigation only Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-56247 Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compatibility, including to pendin… Mitigation only Fix from $1,9502026-06-30 HIGH 8.3 CVE-2026-56233 Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated users with build permissions to b… Mitigation only Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-56230 Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the client-controlled x-limited-key-… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.4 CVE-2026-56224 Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatically authenticating users with… Mitigation only Fix from $1,6002026-06-30