Vulnerability index

Browse CVEs

1,645 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2026-68820 KEV Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-20349 KEV A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T… Adaptive Security Appliance Software No fix yet Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-72898 KEVEPSS 10% Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database endpoint and gain administrator access … Metabase 0.58.24 / 0.59.21+ Fix from $5,7502026-08-10 CRITICAL 9.8 CVE-2026-65400 KEV An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2… macOS 14.8.9 / 15.7.9+ Fix from $2,3002026-08-06 HIGH 8.1 CVE-2026-18577 KEV An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 N Central 2026.3+ Fix from $1,9502026-08-02 HIGH 7.4 CVE-2026-18556 KEV Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-centra… N Central after 2026.1 Fix from $1,9502026-08-01 CRITICAL 9.8 CVE-2026-59310 KEV VMware vCenter contains a directory traversal vulnerability in the Syslog server. A malicious actor with network access to vCenter may exploit this i… Vcenter Server No fix yet Fix from $2,3002026-07-30 MEDIUM 5.3 CVE-2026-20316 KEV A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log… Secure Firewall Management Center after 10.0.1 Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-63077 KEVEPSS 11% In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol Teamcity 2025.11.7 / 2026.1.3+ Fix from $2,3002026-07-27 CRITICAL 10.0 CVE-2026-16812 KEV VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an… Velocloud Orchestrator 5.2.3.14 / 6.1.3.4+ Fix from $2,3002026-07-27 CRITICAL 9.8 CVE-2026-16232 KEVEPSS 73% An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an applicati… Multi Domain Security Management No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-63030 KEVEPSS 96% WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__n… WordPress 6.9.5 / 7.0.2+ Fix from $2,3002026-07-17 MEDIUM 5.9 CVE-2026-60137 KEVEPSS 73% WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which c… WordPress 6.8.6 / 6.9.5+ Fix from $1,6002026-07-17 CRITICAL 9.8 CVE-2026-9198 KEVEPSS 17% IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) wit… Langflow 1.10.1+ Fix from $2,3002026-07-17 HIGH 8.1 CVE-2021-27137 KEVEPSS 16% An issue was discovered in router/upnp/src/ssdp.c in DD-WRT before 45724. An unsafe strcpy in the UPnP handling functionality allows an unauthenticat… Dd Wrt 45724+ Fix from $1,9502026-07-16 HIGH 7.2 CVE-2026-15410 KEVEPSS 76% Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management C… Sma6210 Firmware Mitigation only Fix from $1,9502026-07-14 CRITICAL 10.0 CVE-2026-15409 KEVEPSS 74% A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attack… Sma6210 Firmware Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.1 CVE-2026-55040 KEV Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-58644 KEVEPSS 45% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-56164 KEVEPSS 22% Missing authentication for critical function in Microsoft Office SharePoint allows an unauthorized attacker to elevate privileges over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 HIGH 7.8 CVE-2026-56155 KEV Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locall… Windows 10 1607 10.0.14393.9339 / 10.0.17763.9020+ Fix from $1,9502026-07-14 CRITICAL 9.8 CVE-2026-50522 KEVEPSS 77% Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network. Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-56291 KEVEPSS 76% Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1 - The Joomla extension Balbooa Forms is vulnerable to… Forms 2.4.1+ Fix from $2,3002026-07-09 CRITICAL 10.0 CVE-2026-48282 KEVEPSS 99% ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-56290 KEVEPSS 83% Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl… Page Builder Ck 3.6.0+ Fix from $2,3002026-06-29 HIGH 8.4 CVE-2026-55255 KEVEPSS 29% Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerabili… Langflow 1.9.1+ Fix from $1,9502026-06-23 CRITICAL 9.8 CVE-2026-48939 KEVEPSS 83% A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP… Icagenda 3.9.15 / 4.0.8+ Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2026-48908 KEVEPSS 88% A vulnerability in SP Page Builder for Joomla allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and executio… Sp Page Builder 6.6.2+ Fix from $2,3002026-06-20 CRITICAL 9.8 CVE-2026-12569 KEVEPSS 30% A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited t… Flexplm 11.0m030+ Fix from $2,3002026-06-18 MEDIUM 6.5 CVE-2026-20262 KEVEPSS 28% A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker to create a fi… Catalyst Sd Wan Manager 20.9.9.2 / 20.12.7.2+ Fix from $1,6002026-06-15