Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2026-19960 A security vulnerability has been detected in Edimax EW-7478APC 1.04. This impacts the function formWlbasic of the file /goform/formWlbasic. Such man… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.9 CVE-2026-19959 A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This man… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.3 CVE-2026-19958 A security flaw has been discovered in iatsiuk pptr-mcp up to 0.2.7. The impacted element is the function executeCode of the file src/vm-executor.ts … No fix yet Fix from $4,0002026-08-16 MEDIUM 6.3 CVE-2026-19957 A vulnerability was identified in graphlit graphlit-mcp-server 1.0.1. This affects the function fetch of the file src/tools.ts of the component ssrf-… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.1 CVE-2026-74796 OpenTofu before 1.11.7 fails to validate existing symlinks in the provider cache directory during initialization. Attackers can place a malicious sym… No fix yet Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-74795 Scriban before 6.6.0 contains an uncontrolled recursion vulnerability in its recursive-descent parser. The parser does not enforce a default expressi… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-74794 Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. A… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-74792 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array in… No fix yet Fix from $4,9002026-08-16 HIGH 8.6 CVE-2026-74791 Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist acros… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.1 CVE-2026-74790 Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to e… No fix yet Fix from $5,7502026-08-16 HIGH 7.5 CVE-2026-74789 Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed ins… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-74788 Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_righ… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-74787 Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular ref… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.5 CVE-2026-74786 Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) ca… No fix yet Fix from $4,0002026-08-16 MEDIUM 6.5 CVE-2026-74785 Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through … No fix yet Fix from $4,0002026-08-16 HIGH 8.7 CVE-2026-74784 Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respect… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-74783 Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested… No fix yet Fix from $4,9002026-08-16 HIGH 7.5 CVE-2026-73062 Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enf… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.8 CVE-2026-73061 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties… No fix yet Fix from $5,7502026-08-16 MEDIUM 6.5 CVE-2026-73059 stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requ… No fix yet Fix from $4,0002026-08-16 MEDIUM 5.8 CVE-2026-73058 stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass … No fix yet Fix from $4,0002026-08-16 HIGH 7.5 CVE-2026-73057 stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhau… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.8 CVE-2026-73056 SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware.… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-19349 Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass vi… No fix yet Fix from $5,7502026-08-16 HIGH 7.5 CVE-2024-58375 OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module … No fix yet Fix from $4,9002026-08-16 CRITICAL 9.3 CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specificat… No fix yet Fix from $5,7502026-08-16 HIGH 7.1 CVE-2026-74578 In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->stat… No fix yet Fix from $4,9002026-08-16 CRITICAL 9.8 CVE-2024-13784 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i… No fix yet Fix from $5,7502026-08-16 HIGH 7.2 CVE-2026-2497 The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all version… No fix yet Fix from $4,9002026-08-16 MEDIUM 6.4 CVE-2026-2357 The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions … No fix yet Fix from $4,0002026-08-16