Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Openshift Update Service HIGH 8.2
CVE-2026-74243

A flaw was found in Red Hat Quay. When the SECURITY_SCANNER_V4_PSK (pre-shared key) is not set, a remote unauthenticated attacker can send POST reque…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-74242

A flaw was found in Red Hat Quay. An administrator of any repository, by knowing or guessing a target notification's Universally Unique Identifier (U…

No fix yet
Fix from $4,000 2026-08-14
Openshift Update Service MEDIUM 5.4
CVE-2026-74240

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO) authentication. Multiple iss…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.1
CVE-2026-73683

Laravel Socialite's Facebook provider contains an authentication bypass vulnerability that allows unauthenticated attackers to replay captured OIDC i…

Patch available
Fix from $4,900 2026-08-14
Malware Protection Engine HIGH 7.8
CVE-2026-69414

Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "Shield…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73682

Semaphore versions prior to 2.18.20 contain an OS command injection (argument injection) vulnerability in the repository git_url handling that allows…

Patch available
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.1
CVE-2026-71570

Joomla Extension - icagenda.com - ACL bypass allowing arbitrary user enumeration < 2.0.0-4.0.11 - A backend operator granted access scoped to `com_ic…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-67366

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the fronte…

No fix yet
Fix from $4,000 2026-08-14
Powershell HIGH 7.8
CVE-2026-50523

Improper neutralization of special elements used in a command ('command injection') in Microsoft PowerShell allows an authorized attacker to execute …

Fix: 7.4.19.0 / 7.5.10.0+
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-73680

Cockpit CMS 2.14.0 and prior contains a command injection vulnerability in the FFmpeg integration that allows authenticated users with only the asset…

Patch available
Fix from $4,900 2026-08-14
Unclassified HIGH 8.6
CVE-2026-71571

Joomla Extension - icagenda.com - Authenticated SQL injection via unescaped numeric filter in iCagenda < 2.0.0-4.0.11 - Backend operators with permi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.2
CVE-2026-67365

Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 7.0
CVE-2026-64887

Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.0
CVE-2026-34492

External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.5
CVE-2026-19910

PAX Technology Q80 Application Installer Signature Verification Bypass Remote Code Execution Vulnerability. This vulnerability allows network-adjacen…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.5
CVE-2026-19909

PAX Technology Q80 AIP File Parsing Link Following Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execu…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.1
CVE-2026-19908

PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive inform…

No fix yet
Fix from $4,900 2026-08-14
Db2 Mirror For I HIGH 7.5
CVE-2026-18554

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pa…

Fix: after 7.6
Fix from $4,900 2026-08-14
Db2 Mirror For I HIGH 8.1
CVE-2026-18178

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path traversal.

Fix: after 7.6
Fix from $4,900 2026-08-14
Db2 Mirror For I MEDIUM 6.5
CVE-2026-17227

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due to improper neutralization of …

Fix: after 7.6
Fix from $4,000 2026-08-14
Db2 Mirror For I MEDIUM 5.4
CVE-2026-17209

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to execute arbitrary scripts due to cross-site scripting.

Fix: after 7.6
Fix from $4,000 2026-08-14
Db2 Mirror For I CRITICAL 9.8
CVE-2026-17186

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary CL commands due to improper neutralization of special eleme…

Fix: after 7.6
Fix from $5,750 2026-08-14
Db2 Mirror For I CRITICAL 9.8
CVE-2026-17184

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary code due to external control of file name or path.

Fix: after 7.6
Fix from $5,750 2026-08-14
Db2 Mirror For I CRITICAL 9.8
CVE-2026-17182

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to bypass authentication and obtain or alter sensitive information due to improp…

Fix: after 7.6
Fix from $5,750 2026-08-14
Db2 Mirror For I HIGH 8.6
CVE-2026-17181

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write files to arbitrary locations due to path traversal.

Fix: after 7.6
Fix from $4,900 2026-08-14
Db2 Mirror For I MEDIUM 6.5
CVE-2026-17179

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to command injection.

Fix: after 7.6
Fix from $4,000 2026-08-14
Db2 Mirror For I HIGH 7.5
CVE-2026-17177

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to uncontrolled recursion.

Fix: after 7.6
Fix from $4,900 2026-08-14
Db2 Mirror For I MEDIUM 6.5
CVE-2026-17175

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enf…

Fix: after 7.6
Fix from $4,000 2026-08-14
Db2 Mirror For I MEDIUM 6.5
CVE-2026-17173

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of file…

Fix: after 7.6
Fix from $4,000 2026-08-14
Db2 Mirror For I HIGH 7.5
CVE-2026-17081

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to write arbitrary files due to improper limitation of a pathname to a restricte…

Fix: after 7.6
Fix from $4,900 2026-08-14