Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-24185 NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, wh… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-24184 NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an a… No fix yet Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-24183 NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on… No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-17106 The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.7 CVE-2025-9211 Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers … No fix yet Fix from $4,0002026-08-18 HIGH 8.1 CVE-2025-9210 Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.0 CVE-2026-75625 Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache,… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.0 CVE-2026-75130 Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agent… No fix yet Fix from $5,7502026-08-18 HIGH 7.6 CVE-2026-71880 Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attacker… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-71879 Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 all… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.2 CVE-2026-71878 Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be… No fix yet Fix from $5,7502026-08-18 HIGH 8.1 CVE-2026-67262 Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-66780 A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce… No fix yet Fix from $5,7502026-08-18 MEDIUM 6.1 CVE-2026-52609 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro… No fix yet Fix from $4,0002026-08-18 HIGH 7.3 CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, … No fix yet Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-75924 A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secr… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75897 Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow r… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-73372 Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access che… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.1 CVE-2026-73336 Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in sche… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.1 CVE-2026-72531 Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check … No fix yet Fix from $4,0002026-08-18 MEDIUM 6.9 CVE-2026-71573 Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS… No fix yet Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-70415 Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote acc… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-67271 Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentiall… No fix yet Fix from $5,7502026-08-18 HIGH 8.2 CVE-2026-66783 A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster ad… No fix yet Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-66782 A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token with… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-66781 A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-sha… No fix yet Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-61574 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.1 CVE-2026-52606 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-30250 Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to … No fix yet Fix from $4,0002026-08-18 HIGH 7.6 CVE-2026-19869 @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-le… No fix yet Fix from $4,9002026-08-18