Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-73499

etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permissi…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 7.7
CVE-2026-73498

MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment pa…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 7.4
CVE-2026-73495

blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73493

Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregate…

Patch available
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-71846

A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch perm…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.5
CVE-2026-71473

A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerabil…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-18750

vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the …

Patch available
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.0
CVE-2026-71471

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search …

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 7.5
CVE-2026-71469

A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique tok…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.8
CVE-2026-19003

A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18749

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac…

Patch available
Fix from $5,750 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18744

Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func on…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18727

A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Conf…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-18726

A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in t…

No fix yet
Fix from $4,000 2026-08-12
I HIGH 8.2
CVE-2026-17485

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow.

No fix yet
Fix from $4,900 2026-08-12
Db2 CRITICAL 9.8
CVE-2026-10534

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

Fix: after 12.1.5
Fix from $5,750 2026-08-12
Unclassified CRITICAL 10.0
CVE-2024-27253

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73430

Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73429

Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.1
CVE-2026-73423

Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only t…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73422

Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animatio…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.8
CVE-2026-73419

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC ant…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73418

NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper i…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-65370

ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-66898

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing …

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-64826

rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized di…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-19654

A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.5
CVE-2026-19502

MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-19130

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub clust…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-19004

An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored proced…

No fix yet
Fix from $4,900 2026-08-12