Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-57700 Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n… Mitigation only Fix from $2,3002026-06-25 HIGH 7.5 CVE-2026-56770 libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range se… Mitigation only Fix from $1,9502026-06-25 HIGH 8.2 CVE-2026-55667 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.8 CVE-2026-54250 K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability … Mitigation only Fix from $1,6002026-06-25 HIGH 8.4 CVE-2026-54096 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-54094 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.8 CVE-2026-54093 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $1,6002026-06-25 HIGH 8.7 CVE-2026-54090 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.3… Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.1 CVE-2026-54089 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting wit… Mitigation only Fix from $2,3002026-06-25 CRITICAL 9.3 CVE-2026-54088 File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.6… Mitigation only Fix from $2,3002026-06-25 HIGH 7.8 CVE-2026-53925 Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets … Mitigation only Fix from $1,9502026-06-25 HIGH 7.1 CVE-2026-4930 SYMCRYPTO is the SiXG301's host side hardware engine accessed by PSA crypto library that accelerates symmetric cryptographic operations (AES encrypti… Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-46611 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/serve… Mitigation only Fix from $1,6002026-06-25 HIGH 7.4 CVE-2026-46608 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CO… Mitigation only Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-46607 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache… Mitigation only Fix from $1,9502026-06-25 HIGH 7.8 CVE-2026-46606 Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/… Mitigation only Fix from $1,9502026-06-25 HIGH 8.4 CVE-2026-12897 Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful explo… Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.5 CVE-2026-55439 Halo is an open source website building tool. Prior to 2.24.3, a path traversal vulnerability in the backup download endpoint allows authenticated ad… Mitigation only Fix from $1,6002026-06-25 CRITICAL 9.4 CVE-2026-55413 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts… Mitigation only Fix from $2,3002026-06-25 HIGH 8.3 CVE-2026-55412 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-lts… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.8 CVE-2026-55411 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.1780-lt… Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-54573 Outline is a service that allows for collaborative documentation. Prior to 1.8.0, the AuthenticationHelper.canAccess function uses ctx.originalUrl to… Mitigation only Fix from $1,6002026-06-25 HIGH 8.1 CVE-2026-45233 HTMLy CMS through 3.1.1 contains a path traversal vulnerability that allows low-privileged authenticated attackers to relocate arbitrary files by sup… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.7 CVE-2026-9651 CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential… Mitigation only Fix from $1,6002026-06-25 HIGH 7.2 CVE-2026-55477 3X-UI is a web control panel for managing Xray-core servers. Prior to 3.3.1, an authenticated administrator can abuse the database import functionali… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.7 CVE-2026-4522 Missing authentication for critical function vulnerability in HYPR Passwordless on Windows allows Credentials Interception. This issue affects HYPR … Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-6432 Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage. Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.3 CVE-2026-57536 Our payment integration with Mollie did not properly validate payment status responses. An attacker could use a successful payment status response … Mitigation only Fix from $1,6002026-06-25 HIGH 8.8 CVE-2026-57532 Malicious HTML content contained in the layout specification of a PDF ticket or badge layout was executed when the PDF editor is opened in the brow… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-49319 Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-… Mitigation only Fix from $1,6002026-06-25