Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

PostgreSQL MEDIUM 6.5
CVE-2026-14663

Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a user to recover cleartext, via direct observation of the faulty ciphertext. The O…

Fix: 14.24 / 15.19+
Fix from $4,000 2026-08-13
PostgreSQL HIGH 8.8
CVE-2026-14662

Integer wraparound in PostgreSQL tsvector and tsquery data type functions allows an unprivileged database user to cause the server to undersize an al…

Fix: 14.24 / 15.19+
Fix from $4,900 2026-08-13
Unclassified HIGH 8.5
CVE-2026-73629

Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.1
CVE-2026-73628

Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In …

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.0
CVE-2026-73627

JupyterLab (pip package 'jupyterlab') versions >=4.1.0,<=4.5.9 and >=4.6.0,<=4.6.1 contain a plugin manager lock-rule enforcement bypass. Two server-…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73625

GitPython versions before 3.1.54 contain a remote code execution vulnerability in the check_unsafe_options guard that can be bypassed by smuggling gi…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73624

GitPython versions before 3.1.54 contain an arbitrary file overwrite vulnerability in the Diffable.diff method that fails to validate git options pas…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73623

GitPython before 3.1.54 contains an incomplete denylist in unsafe_git_clone_options that omits --template, allowing attackers to achieve arbitrary co…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-73622

GitPython before 3.1.55 fails to disable environment variable expansion in Remote.create() and Submodule.add() URL handling, allowing attackers to ex…

Patch available
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-73621

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keyword arguments to 'git rev-list'…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73620

GitPython before 3.1.57 fails to guard git option forwarding in IndexFile.checkout() and TagReference.create(), allowing attackers to pass unsafe opt…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73619

GitPython before 3.1.57 contains an incomplete denylist in the unsafe_git_archive_options guard that omits --add-file and --add-virtual-file options.…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.3
CVE-2026-73618

Budibase Server before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB query execution endpoint where user-supplied parameters are int…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.1
CVE-2026-73617

Budibase before 3.40.0 contains a NoSQL injection vulnerability in the MongoDB datasource integration where user-supplied parameters are enriched wit…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73616

OpenRemote notification deletion endpoints fail to enforce realm boundaries, allowing any realm administrator to delete notifications belonging to ot…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73615

Network-AI versions before 5.15.1 contain a security matcher bypass vulnerability where SandboxPolicy evaluates raw command strings with quotes prese…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73614

Network-AI ClaudeHookBridge before 5.15.1 truncates the target string to 500 characters before evaluating denyPatterns, while Claude Code executes th…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73613

filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authen…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 8.1
CVE-2026-73612

File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authentica…

Patch available
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.8
CVE-2026-73611

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout p…

Patch available
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73610

SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the administrator's entire storage map…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73609

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that returns all bookmark labels in t…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73608

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4) contains a missing-authoriz…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73607

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endpoint that performs no authori…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73606

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that fails to check password-prote…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.8
CVE-2026-73605

SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anonymous readers to probe filesys…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.5
CVE-2026-73604

Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted sec…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.3
CVE-2026-73603

Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatfl…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73602

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code …

Patch available
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73601

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing…

No fix yet
Fix from $5,750 2026-08-13