Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-36908 A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a… No fix yet Fix from $1,6002026-06-26 MEDIUM 5.5 CVE-2026-36907 A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (… Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-36478 An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll,… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.5 CVE-2026-39031 Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix… Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-38641 An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted shared … Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-38639 An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a cr… Mitigation only Fix from $1,9502026-06-26 HIGH 7.7 CVE-2026-55189 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, when the FTP frontend is enabled, the FTP read an… Mitigation only Fix from $1,9502026-06-26 HIGH 8.2 CVE-2026-55188 RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.1 until 1.0.0-beta.9, RustFS contains an authorization bypass in the bu… Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.9 CVE-2026-52785 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. … Mitigation only Fix from $2,3002026-06-26 HIGH 8.8 CVE-2026-52784 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a CSRF on TARGET through /users/:id via POST … Mitigation only Fix from $1,9502026-06-26 HIGH 8.2 CVE-2026-52783 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, OpenProject's Storages module writes the OneDrive/Shar… Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.9 CVE-2026-52782 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/projec… Mitigation only Fix from $2,3002026-06-26 MEDIUM 6.4 CVE-2026-52781 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the HTML sanitizer grants <macro> elements unrestricte… Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.6 CVE-2026-52780 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (… Mitigation only Fix from $2,3002026-06-26 MEDIUM 5.4 CVE-2026-52779 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, a cross-project IDOR / authorization context confusion… Mitigation only Fix from $1,6002026-06-26 HIGH 8.6 CVE-2026-49991 RustFS is a distributed object storage system built in Rust. In 1.0.0-beta.4, authenticated users with only PutObject permission on their own bucket … Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-47193 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, the journal diff endpoint discloses hidden historical … Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.9 CVE-2026-46386 OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_… Mitigation only Fix from $2,3002026-06-26 MEDIUM 6.5 CVE-2026-44736 OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user … Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-44735 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, the GET /api/v3/shares endpoint returns share details … Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-44734 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenPr… Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.9 CVE-2026-44733 OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, Business Logic Error on OpenProject through PATCH requ… Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.7 CVE-2026-44696 OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Saniti… Mitigation only Fix from $1,6002026-06-26 HIGH 8.8 CVE-2026-32833 Cudy LT300 3.0 running firmware prior to version 2.5.12 contains an OS command injection vulnerability that allows authenticated attackers to execute… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.4 CVE-2026-29509 Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python … Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.3 CVE-2026-55448 mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local projec… Mitigation only Fix from $1,6002026-06-26 HIGH 8.6 CVE-2026-55441 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.5 CVE-2026-54557 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from … Mitigation only Fix from $1,6002026-06-26 CRITICAL 9.6 CVE-2026-33646 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template eng… Mitigation only Fix from $2,3002026-06-26 HIGH 8.8 CVE-2026-57518 Pagekit CMS 1.0.18 contains a privilege escalation vulnerability that allows authenticated users with the 'user: manage users' permission to escalate… Mitigation only Fix from $1,9502026-06-26