Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-74940 Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.… Firefox Fix unknown Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-74936 Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderb… Firefox Fix unknown Fix from $5,7502026-08-18 MEDIUM 5.4 CVE-2026-59781 When Zabbix Agent was installed on Windows into a custom installation directory, the installer did not verify whether the selected directory had secu… No fix yet Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-45532 DataEase is an open source data visualization and analysis tool. Versions prior to 2.10.23 have a path traversal vulnerability. The root cause is tha… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.0 CVE-2026-23937 The Zabbix API host.get action can be exploited by authenticated users to extract a host's PSK key leading to potential loss of data integrity. No fix yet Fix from $4,0002026-08-18 MEDIUM 6.8 CVE-2026-23935 A Zabbix administrator is able to read out of bounds memory by utilizing a flaw in script item/preprocessing (JavaScript) HttpRequest logic, leading … No fix yet Fix from $4,0002026-08-18 MEDIUM 5.1 CVE-2026-23934 An authenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend v… No fix yet Fix from $4,0002026-08-18 HIGH 7.7 CVE-2026-23933 In Zabbix 7.4 the cryptographic key used for signing Frontend sessions has been erroneously written to the database seed. Currently the only known ex… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-23931 The frontend validatate.api.exists action can be exploited by authenticated users to extract plaintext user macro values leading to potential loss of… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-23930 An unauthenticated user is able to cause disproportionate CPU load on the Frontend webserver by sending specifically crafted requests to the Frontend… No fix yet Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-23929 Prototype pollution vulnerability in searchParamsToObject() is leading to a persistent XSS in Maps. URL parameter processing was not filtering danger… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.9 CVE-2026-1199 Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block count… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.2 CVE-2026-18751 External control of file name or path vulnerability in Citrix WorkSpace App on MacOS. This issue affects WorkSpace App: 2607. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-16309 Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly… No fix yet Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-75855 ArcadeDB versions before 26.8.1 fail to sanitize database names in the POST /api/v1/server endpoint's create database and drop database commands, all… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-75854 ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attacker… No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-75853 ArcadeDB's Gremlin wire-protocol plugin (com.arcadedb:arcadedb-gremlin) in versions <= 26.7.3 enforces authentication (SASL PLAIN) but performs no au… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-75852 ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers c… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.9 CVE-2026-75851 ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command … No fix yet Fix from $5,7502026-08-18 HIGH 7.1 CVE-2026-75846 ArcadeDB before 26.8.1 (affected versions <= 26.7.3) contains a missing authorization vulnerability in the DELETE FUNCTION SQL statement. DeleteFunct… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75845 ArcadeDB versions 26.4.2 through 26.7.3 contain an authorization bypass vulnerability in the set_server_setting MCP server-level tool. SetServerSetti… No fix yet Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-75844 ArcadeDB versions before 26.8.1 contain a server-side request forgery vulnerability in the IMPORT DATABASE command where the security validator resol… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-75843 ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated … No fix yet Fix from $5,7502026-08-18 HIGH 7.7 CVE-2026-75842 ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users t… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75840 ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped re… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-75838 DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detache… No fix yet Fix from $4,0002026-08-18 CRITICAL 9.1 CVE-2026-75837 Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi… No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-75836 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-75834 Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). … No fix yet Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-75830 grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batc… No fix yet Fix from $4,9002026-08-18