Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-9154 Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content t… Sed Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-9153 Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the express… Sed Mitigation only Fix from $1,6002026-06-25 HIGH 8.1 CVE-2026-55762 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, th… Mitigation only Fix from $1,9502026-06-24 HIGH 7.4 CVE-2026-55759 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Ro… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.3 CVE-2026-55666 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.0 CVE-2026-55570 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, descri… Mitigation only Fix from $2,3002026-06-24 HIGH 8.7 CVE-2026-54759 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, Lute's HTML sanitizer does not remove <iframe> elements. Combined with… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.9 CVE-2026-54158 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolate… Mitigation only Fix from $2,3002026-06-24 HIGH 7.1 CVE-2026-54070 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, renderPackageREADME in kernel/bazaar/readme.go renders a Bazaar packag… No fix yet Fix from $1,9502026-06-24 CRITICAL 9.2 CVE-2026-54069 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-ext… Mitigation only Fix from $2,3002026-06-24 MEDIUM 5.9 CVE-2026-54068 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the /api/icon/getDynamicIcon endpoint is explicitly excluded from auth… Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.9 CVE-2026-54067 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <st… Mitigation only Fix from $2,3002026-06-24 HIGH 7.5 CVE-2026-54066 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the patch for CVE-2026-41894 ("Path Traversal via Double URL Encoding"… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.9 CVE-2026-50551 SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan contains a stored cross-site scripting (XSS) vulnerability in t… Mitigation only Fix from $2,3002026-06-24 HIGH 7.8 CVE-2026-2050 GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary… Gimp Mitigation only Fix from $1,9502026-06-24 HIGH 7.3 CVE-2026-7539 A potential security vulnerability has been identified in the HP Accessory WMI Provider installer for some HP Docking Stations, which might allow esc… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.5 CVE-2026-52815 Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/or… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.8 CVE-2026-52809 Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-a… Mitigation only Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-52799 Gogs is an open source self-hosted Git service. Prior to 0.14.3, GET /attachments/:uuid returns the raw attachment file without verifying whether the… Mitigation only Fix from $1,9502026-06-24 HIGH 8.5 CVE-2026-52797 Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the value which is passed to the git … Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-50129 Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.5.11, 4.4.18, and 4.3.24, a DoS can be triggered by (Uncaught … Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-50128 Mastodon is a free, open-source social network server based on ActivityPub. From 4.3.0 until 4.5.11 and 4.4.18, Mastodon has a feature to let website… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.7 CVE-2026-49278 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.2, 8.3.4, 8.2.4, 8.1.5, 8.0.6, 7.13.8, and 7.1… Mitigation only Fix from $1,6002026-06-24 CRITICAL 9.3 CVE-2026-46423 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-45689 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $2,3002026-06-24 CRITICAL 9.1 CVE-2026-45688 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $2,3002026-06-24 HIGH 8.5 CVE-2026-45687 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $1,9502026-06-24 HIGH 8.7 CVE-2026-45677 Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3, 8.1.4, 8.0.5, 7.13.7, and 7.1… Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.3 CVE-2026-33543 FOSSBilling is a free, open-source billing and client management system. Versions 0.7.2 and prior expose a guest API endpoint, /api/guest/staff/creat… Mitigation only Fix from $2,3002026-06-24 HIGH 7.7 CVE-2026-33235 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. In versions prior to 0.6.5… Mitigation only Fix from $1,9502026-06-24