Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-73663

FreePBX is an open source IP PBX. From 16.0.0 until 16.0.11 and 17.0.4, the FreePBX missedcall module places the inbound Caller ID name from crafted …

Patch available
Fix from $5,750 2026-08-13
Unclassified HIGH 7.6
CVE-2026-73662

FreePBX is an open source IP PBX. From 17.0.1 until 17.0.7, the FreePBX Music on Hold module permits dangerous command-line options for /usr/bin/mpg1…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73661

FreePBX is an open source IP PBX. Prior to 16.0.47 and 17.0.30, the FreePBX Framework module permits a crafted backup to restore the hidden AUTHTYPE …

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73660

FreePBX is an open source IP PBX. Prior to 16.0.6 and 17.0.5.4, the FreePBX Text-To-Speech module allows an authenticated administrator to save a TTS…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73659

Trigger.dev is the open-source platform for building AI workflows in TypeScript. From 4.4.2 until 4.5.0, the packet presign routes in apps/webapp/app…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73658

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. From 4.4.2 until 4.5.0-rc.5, Aws4FetchClient.buildUrl() a…

Patch available
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.0
CVE-2026-73479

dua-cli fails to filter terminal escape sequences when printing marked file paths after exiting the TUI interface. Attackers can craft file names con…

Patch available
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-73421

NextAuth.js provides authentication for Next.js. From next-auth 5.0.0-beta.0 until 5.0.0-beta.32, applications that gate access by checking only for …

Patch available
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-73420

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the defaultNormalizer used by th…

Patch available
Fix from $5,750 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73417

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 3.3.0 until 4.5.…

Patch available
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73416

jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. From 4.5.0 until 4.5.…

Patch available
Fix from $4,000 2026-08-13
Unclassified HIGH 7.6
CVE-2026-73408

Budibase is an open-source low-code platform. Prior to 3.39.18, packages/server/src/integrations/mysql.ts enabled multipleStatements and inserted an …

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73305

Budibase is an open-source low-code platform. Prior to 3.39.24, POST /api/public/v1/roles/assign called validateGlobalRoleUpdate without checking app…

Patch available
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73302

Budibase is an open-source low-code platform. Prior to 3.39.30, the OIDC flow in packages/backend-core/src/middleware/passport/sso/oidc.ts resolved a…

Patch available
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-73039

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete othe…

Patch available
Fix from $4,000 2026-08-13
Unclassified HIGH 7.7
CVE-2026-72857

Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-72856

Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) end…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.5
CVE-2026-72855

Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.6
CVE-2026-72853

Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table n…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-72851

Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers c…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-72850

Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 7.7
CVE-2026-72849

Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an externa…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-72842

luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management r…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-72841

luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal a…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.8
CVE-2026-72840

OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended …

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-72839

filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthen…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-72776

AgenticSeek (commit fc242c7) contains an unauthenticated remote code execution vulnerability that allows any network-adjacent attacker to execute arb…

Patch available
Fix from $5,750 2026-08-13
Unclassified HIGH 8.4
CVE-2026-56865

A malicious GOPROXY was previously capable of forging up to two sumdb tiles that allow for a requested module to bypass the GOSUMDB check and persist…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-56864

A malicious GOSUMDB was capable of serving arbitrary module content not contained within the transparency log. This attack allows for a coordinating …

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-56862

Handshake messages, such as KeyUpdate, are always considered as state-advancing, regardless of whether a handshake has been completed or not. As a re…

No fix yet
Fix from $4,900 2026-08-13