Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-72786

Craft CMS versions before 5.10.8 contain an authentication bypass vulnerability in the elements/save action that allows authenticated users to change…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-72508

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a names…

No fix yet
Fix from $5,750 2026-08-12
Ash Framework HIGH 7.4
CVE-2026-67579

Deserialization of Untrusted Data vulnerability in ash-project ash allows an unauthenticated attacker to inject a filter expression through a forged …

Fix: 3.31.3+
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63300

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_c…

Patch available
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63299

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63298

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63297

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63296

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63294

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63293

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-62420

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project ins…

Patch available
Fix from $5,750 2026-08-12
Display And Peripheral Manager HIGH 7.8
CVE-2026-59917

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attac…

Fix: 2.3.0.17+
Fix from $4,900 2026-08-12
Display And Peripheral Manager HIGH 7.8
CVE-2026-59916

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain Improper Access Control vulnerability. A low privileged attac…

Fix: 2.3.0.17+
Fix from $4,900 2026-08-12
Display And Peripheral Manager HIGH 7.8
CVE-2026-59914

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low pri…

Fix: 2.3.0.17+
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-49466

Draft List is a WordPress plugin to manage and promote unpublished content. Versions 2.6.3 and below are vulnerable to stored Cross-Site Scripting (X…

No fix yet
Fix from $4,000 2026-08-12
Display And Peripheral Manager HIGH 7.8
CVE-2026-46731

Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3.0.17, contain an Authentication Bypass by Spoofing vulnerability. A low pri…

Fix: 2.3.0.17+
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-19657

ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visitin…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-19656

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil…

No fix yet
Fix from $5,750 2026-08-12
Aws Software Development Kit MEDIUM 5.3
CVE-2026-19643

An out-of-bounds read issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862, on some platforms, might allow a remote authenticated user t…

Fix: 1.11.862+
Fix from $4,000 2026-08-12
Aws Software Development Kit MEDIUM 5.9
CVE-2026-19642

An out-of-bounds write issue in the Base64 decoder in Amazon aws-sdk-cpp before 1.11.862 might allow a remote authenticated user to cause a crash or …

Fix: 1.11.862+
Fix from $4,000 2026-08-12
GitLab HIGH 8.5
CVE-2026-19228

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could…

Fix: 19.1.4 / 19.2.2+
Fix from $4,900 2026-08-12
I MEDIUM 5.3
CVE-2026-18150

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to a race condition.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.8
CVE-2026-18679

When kuma-dp is started against an HTTPS control plane and the operator did not pass a CA certificate, the data plane connects with TLS peer verifica…

Patch available
Fix from $4,000 2026-08-12
I MEDIUM 5.4
CVE-2026-18099

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary script code due to improper neutralization of user-cont…

No fix yet
Fix from $4,000 2026-08-12
I HIGH 8.8
CVE-2026-17642

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elem…

No fix yet
Fix from $4,900 2026-08-12
I MEDIUM 6.5
CVE-2026-17445

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper validation of an attacker-su…

No fix yet
Fix from $4,000 2026-08-12
I HIGH 8.8
CVE-2026-17417

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of shell metach…

No fix yet
Fix from $4,900 2026-08-12
I CRITICAL 9.8
CVE-2026-17111

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…

No fix yet
Fix from $5,750 2026-08-12
I CRITICAL 9.8
CVE-2026-17083

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

No fix yet
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-17082

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of a client-supplied …

No fix yet
Fix from $4,900 2026-08-12