Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.8
CVE-2026-12366

Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its ref…

Patch available
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.8
CVE-2026-12365

A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work …

Patch available
Fix from $4,000 2026-08-14
Unclassified HIGH 8.4
CVE-2026-12364

The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-sup…

Patch available
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-73846

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request paramete…

Patch available
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-73845

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s…

Patch available
Fix from $4,000 2026-08-14
Unclassified HIGH 7.1
CVE-2026-49989

CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.1
CVE-2026-49986

The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` enviro…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.1
CVE-2026-47766

crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev`…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.5
CVE-2026-46603

VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffm…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.8
CVE-2026-46439

compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (S…

Patch available
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.7
CVE-2026-46380

compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method pas…

Patch available
Fix from $4,000 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19845

A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.c…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19844

A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi…

No fix yet
Fix from $4,900 2026-08-14
Security Center HIGH 7.2
CVE-2026-19628

A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to …

Fix: 6.9.0+
Fix from $4,900 2026-08-14
Security Center CRITICAL 9.9
CVE-2026-19626

A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user …

Fix: 6.9.0+
Fix from $5,750 2026-08-14
Wyse Management Suite MEDIUM 5.3
CVE-2026-66272

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticate…

Fix: 2605.0.2+
Fix from $4,000 2026-08-14
Wyse Management Suite HIGH 7.2
CVE-2026-66271

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…

Fix: 2605.0.2+
Fix from $4,900 2026-08-14
Wyse Management Suite HIGH 7.2
CVE-2026-66270

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil…

Fix: 2605.0.2+
Fix from $4,900 2026-08-14
Wyse Management Suite MEDIUM 5.5
CVE-2026-63702

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with l…

Fix: 2605.0.2+
Fix from $4,000 2026-08-14
Wyse Management Suite HIGH 7.8
CVE-2026-63701

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged a…

Fix: 2605.0.2+
Fix from $4,900 2026-08-14
Wyse Management Suite HIGH 7.8
CVE-2026-63700

Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with l…

Fix: 2605.0.2+
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.9
CVE-2026-57472

Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.8
CVE-2026-57471

Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.1
CVE-2026-57469

Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory i…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.5
CVE-2026-53970

ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers…

Patch available
Fix from $4,900 2026-08-14
Unclassified HIGH 8.4
CVE-2026-19884

In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the fold…

Patch available
Fix from $4,900 2026-08-14
Unclassified HIGH 8.1
CVE-2026-16772

In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.9
CVE-2026-13198

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability …

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.3
CVE-2026-13197

Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability …

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-13196

Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in ver…

No fix yet
Fix from $4,900 2026-08-14