Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.0
CVE-2026-73488

Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpo…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73487

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73486

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73485

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73484

Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_cs…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73483

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 6.6
CVE-2026-45819

baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immed…

Patch available
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.0
CVE-2026-18368

In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthentic…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.9
CVE-2026-16455

In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exis…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.8
CVE-2026-12263

Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabi…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-59507

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-59506

CWE-306: Missing Authentication for Critical Function

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.6
CVE-2026-59505

CWE-284: Improper Access Control

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-59504

CWE-602: Client-Side Enforcement of Server-Side Security

No fix yet
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-59503

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-59502

CWE-203: Observable Discrepancy

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.2
CVE-2026-59501

CWE-284: Improper Access Control

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-59500

CWE-287: Improper Authentication

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.6
CVE-2026-59499

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.5
CVE-2026-19484

@fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop …

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 6.6
CVE-2026-19696

Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.5
CVE-2026-19481

@fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-16459

Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an att…

No fix yet
Fix from $4,000 2026-08-13
Unclassified MEDIUM 5.9
CVE-2026-16458

Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to r…

No fix yet
Fix from $4,000 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-15413

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp…

No fix yet
Fix from $5,750 2026-08-13
Unclassified MEDIUM 5.4
CVE-2026-14332

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its…

No fix yet
Fix from $4,000 2026-08-13
Mattermost Server MEDIUM 6.5
CVE-2026-14298

Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when proces…

Fix: 10.11.23 / 11.7.8+
Fix from $4,000 2026-08-13
Unclassified MEDIUM 6.4
CVE-2026-3639

The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in a…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 8.8
CVE-2026-11840

Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL inj…

No fix yet
Fix from $4,900 2026-08-13
Unclassified HIGH 7.2
CVE-2026-18146

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc…

No fix yet
Fix from $4,900 2026-08-13