Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-56219 Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that allows unauthenticated attackers… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.3 CVE-2026-55721 Storage Concentrator (SC & SCVM) is vulnerable to SQL injection through cookie values processed by the login.pl and debug.pl scripts. The cookie valu… Mitigation only Fix from $2,3002026-06-30 HIGH 7.5 CVE-2026-52198 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_425… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-52197 An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_44af70 component Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-52195 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_472… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-52193 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_447… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.2 CVE-2026-50110 Storage Concentrator (SC & SCVM) contains hardcoded credentials for numerous internal services embedded within a configuration file. While the creden… Mitigation only Fix from $2,3002026-06-30 MEDIUM 6.1 CVE-2026-50040 Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An … Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.6 CVE-2026-28322 SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to u… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2025-71381 Hono before 4.10.2 (fixed in 4.10.3) contains a flaw in its CORS middleware: when the origin is not set to "*", the middleware copies the Vary header… Mitigation only Fix from $1,6002026-06-30 HIGH 8.1 CVE-2025-71374 picklescan before 0.0.29 fails to detect the built-in python profile.Profile.run function when used in pickle reduce methods, allowing attackers to e… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71371 picklescan before 0.0.29 fails to detect malicious pickle files using code.InteractiveInterpreter.runcode in reduce methods. Attackers can craft pick… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71368 picklescan before 0.0.30 fails to detect the doctest.debug_script function when analyzing pickle files, allowing attackers to execute arbitrary code.… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71363 picklescan before 0.0.30 fails to detect cProfile.run function calls in pickle reduce methods, allowing attackers to execute arbitrary code. Remote a… Mitigation only Fix from $1,9502026-06-30 HIGH 7.6 CVE-2025-71355 Picklescan before 0.0.25 fails to detect unsafe global functions in the Numpy library, allowing attackers to bypass static analysis and execute arbit… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71352 picklescan before 0.0.29 fails to detect the built-in Python trace.Trace.runctx function when used in pickle file reduce methods, allowing attackers … Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71350 picklescan before 0.0.28 fails to detect malicious pickle files using torch.utils.collect_env.run function in reduce methods. Attackers can embed und… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2025-71349 picklescan before 0.0.29 fails to detect the built-in trace.Trace.run function when analyzing pickle files, allowing attackers to embed undetected ma… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.5 CVE-2026-58448 yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary pr… No fix yet Fix from $1,6002026-06-30 HIGH 8.2 CVE-2026-52868 An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment,… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-52196 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_416… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-50254 An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-pro… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-50003 A malicious or compromised server can make a DCMTK client using bit-preserving C-GET storage mode write files outside the chosen output directory, us… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-37106 An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remote attacker to create an account via the register function in inc/auth.php. NOTE: this… Mitigation only Fix from $2,3002026-06-30 HIGH 7.5 CVE-2026-35505 An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows unt… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-44628 An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-13207 FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fails… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.9 CVE-2026-10562 An unauthenticated URL redirection vulnerability has been identified in Archer AX20 V2 due to improper validation of user-supplied URL input within t… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2025-36359 IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to imp… Devops Automation Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2025-36336 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 transmits data in clear text that could allow an attacker to obtain sensitive information us… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30