Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

I CRITICAL 9.1
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b…

No fix yet
Fix from $5,750 2026-08-13
I HIGH 8.8
CVE-2026-16722

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain unauthorized privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
Documentation Offline MEDIUM 5.3
CVE-2026-16713

IBM Documentation Offline 1.0.0 through 1.4.1 IBM Documentation could allow a remote attacker to obtain sensitive information due to a security misco…

Fix: 1.5.1+
Fix from $4,000 2026-08-13
I MEDIUM 6.5
CVE-2026-16692

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-based buffer overflow.

No fix yet
Fix from $4,000 2026-08-13
I HIGH 8.8
CVE-2026-16674

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an untrusted search path.

No fix yet
Fix from $4,900 2026-08-13
I Access Client Solutions HIGH 7.8
CVE-2026-14875

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi…

Fix: 1.1.9.14+
Fix from $4,900 2026-08-13
Websphere Application Server CRITICAL 9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…

Fix: 26.0.0.9+
Fix from $5,750 2026-08-13
Storage Scale HIGH 7.5
CVE-2026-13460

IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 GUI contains a hardcoded token in the source code, which was used for inter-no…

Fix: 5.2.3.9 / 6.0.1.1+
Fix from $4,900 2026-08-13
Planning Analytics Local MEDIUM 6.5
CVE-2026-13365

IBM Planning Analytics 2.0, and 2.1 Local is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthor…

Fix: 2.1.23+
Fix from $4,000 2026-08-13
Websphere Application Server MEDIUM 5.3
CVE-2026-10571

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by a denial of service caused by insecure deserialization. A low-pri…

Fix: 26.0.0.9+
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…

Patch available
Fix from $5,750 2026-08-13
Unclassified HIGH 7.1
CVE-2026-73652

vantage6 is an open-source infrastructure for privacy preserving analysis. In version 5.0.2 and earlier, the algorithm-store edit permission lacks an…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.7
CVE-2026-73651

TypeORM is a TypeScript and JavaScript ORM for Node.js that supports PostgreSQL, MySQL, MariaDB, SQLite, SQL Server, Oracle, and other databases. Pri…

Patch available
Fix from $4,000 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73650

SVGO, short for SVG Optimizer, is a Node.js library and command-line application for optimizing SVG files. From version 1.0.0 until versions 2.8.3, 3…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73482

phpList before 3.7.0-RC5 contains a cross-site request forgery (CSRF) vulnerability in lists/admin/admins.php. The administrator deletion action is t…

Patch available
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-73481

phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / bouncerule.php). The deletion …

Patch available
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73038

NodeBB before 4.15.0 contains a stored cross-site scripting vulnerability in the renderEmoji function that fails to escape tag.icon.url and tag.name …

Patch available
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73037

Next AI Draw.io 0.2.1 through 0.4.16 contains a reflected cross-site scripting vulnerability in the mcp query parameter that is interpolated without …

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.6
CVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint due to hostname validation th…

No fix yet
Fix from $4,900 2026-08-13
I HIGH 7.8
CVE-2026-18071

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to gain elevated privileges due to improper privilege management.

No fix yet
Fix from $4,900 2026-08-13
I HIGH 8.2
CVE-2026-17220

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and modify authentication metadata due to a buffer overflow.

No fix yet
Fix from $4,900 2026-08-13
I CRITICAL 9.8
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-73649

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr…

Patch available
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.1
CVE-2026-73648

rails-html-sanitizer is responsible for sanitizing HTML fragments in Rails applications. From 1.0.3 until 1.7.1, Rails::HTML::PermitScrubber restrict…

Patch available
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.6
CVE-2026-73647

Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.22.0, the public extend() utility in ui/src/utils/ex…

Patch available
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.6
CVE-2026-73645

OpenZeppelin Confidential Contracts is an experimental library for developing applications on the Zama fhEVM. Prior to 0.3.1, the ERC7984 contract tr…

Patch available
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-73644

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org…

Patch available
Fix from $5,750 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73643

js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an application c…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.7
CVE-2026-73569

fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From 5.9.3 until 5.10.1, src/xmlparser/Ordered…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73568

py-libp2p is the Python implementation of the libp2p networking stack. In 0.7.0 and earlier, the yamux handle_incoming() method in libp2p/stream_muxe…

Patch available
Fix from $4,900 2026-08-13