Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-65640 WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisit… No fix yet Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-54356 Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts an… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-39255 Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-39254 Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAu… No fix yet Fix from $5,7502026-08-17 HIGH 7.8 CVE-2026-34399 FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untr… No fix yet Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-19589 Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead t… No fix yet Fix from $4,9002026-08-17 HIGH 7.3 CVE-2026-75014 A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_… No fix yet Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-75013 A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The … No fix yet Fix from $4,0002026-08-17 MEDIUM 6.5 CVE-2026-75012 A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the fi… No fix yet Fix from $4,0002026-08-17 HIGH 7.7 CVE-2026-74234 Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's … No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-68004 An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-lev… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67678 File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-71472 A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource… No fix yet Fix from $5,7502026-08-17 HIGH 8.8 CVE-2026-70495 A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and g… No fix yet Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-68005 An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_req… No fix yet Fix from $4,9002026-08-17 HIGH 7.1 CVE-2026-19650 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.4 CVE-2026-19478 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef… No fix yet Fix from $5,7502026-08-17 MEDIUM 6.3 CVE-2026-75011 A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argum… No fix yet Fix from $4,0002026-08-17 HIGH 7.5 CVE-2026-74238 TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote a… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.9 CVE-2026-66792 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileg… No fix yet Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-50776 Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute … No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-50775 A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, an… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50774 An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. No fix yet Fix from $5,7502026-08-17 HIGH 7.8 CVE-2026-50773 An issue in CGM Germany - CompuGroup Medical CGM ISIS MED 2510.1.0.20 allows a remote attacker to execute arbtirary code via a crafted .dll file. No fix yet Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-45698 Netatalk is a Free and Open Source file server suite for Unix-like operating systems. In versions 3.1.19 through 4.4.2, a stack-based buffer overflow… No fix yet Fix from $4,9002026-08-17 MEDIUM 6.9 CVE-2026-17639 Certain HP Smart Tank All-in-One printers may be potentially vulnerable to a denial of service condition that allows an unauthenticated attacker to c… No fix yet Fix from $4,0002026-08-17 HIGH 8.9 CVE-2026-12553 HP has identified a potential vulnerability in HP Web Jetadmin (WJA) that may allow an unauthenticated actor to read from or write to arbitrary files… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.3 CVE-2026-74254 Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection iss… No fix yet Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-74253 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer befor… No fix yet Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-73523 COVESA Open1722 through 0.9.2 contains an integer truncation vulnerability in acf-can-listener.c that allows unauthenticated remote attackers to caus… No fix yet Fix from $4,9002026-08-17