Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-72839 filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthen… No fix yet Fix from $5,7502026-08-13 HIGH 8.4 CVE-2026-56865 A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-56864 A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating … No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-56862 Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a re… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-56860 Previously, resolving relative paths containing parent directory ('..') segments performed string conversions and buffer rewrites on each step, resul… No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-56859 Previously, DecodeElement would reset the depth counter causing it to never fire; this could lead to stack exhaustion. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.1 CVE-2026-56858 Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially lead… No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-56853 When a server is configured to support unencrypted HTTP/2, it reads a few bytes from each new connection to see if they contain the HTTP/2 client pre… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-33818 Enforce a recursion limit in Unmarshal to prevent stack exhaustion when parsing deeply-nested, recursive structures. No fix yet Fix from $4,9002026-08-13 MEDIUM 6.3 CVE-2026-19752 A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. This affects the function parse-pdf of t… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-19751 A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.g… No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-19750 A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/V27.x. Affected by this issue is some unknown functionality of the component SS… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.6 CVE-2026-8715 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication conf… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.1 CVE-2026-19297 IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of exce… No fix yet Fix from $5,7502026-08-13 MEDIUM 6.5 CVE-2026-18715 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to improper processing of XML external e… I No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-18671 IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused by an integer overflow during… I No fix yet Fix from $4,0002026-08-13 HIGH 7.8 CVE-2026-18511 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to generate a stack-based buffer overflow in the Native IBM i JSSE provider, … I No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-18509 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local authenticated attacker to gain privilege escalation via the Navigator for i debugger. This could all… I No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-18086 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary code or cause a denial of service due to improper bounds checking. I No fix yet Fix from $4,0002026-08-13 CRITICAL 9.9 CVE-2026-18249 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from… I No fix yet Fix from $5,7502026-08-13 CRITICAL 10.0 CVE-2026-18193 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. I No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-18101 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper management of thread authority swaps. I No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-18077 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a stack-based buffer overflow. I No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-17476 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write. I No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-18020 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an off-by-one error in bounds checking. I No fix yet Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-17649 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read. I No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-17502 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write. I No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-17473 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to read arbitrary files due to improper limitation of a pathname to a res… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-17468 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to forge valid session tokens due to the use of a hardcoded cryptographic… No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-17272 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to a buffer overflow. I No fix yet Fix from $4,9002026-08-13