Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

GitLab HIGH 7.1
CVE-2026-16494

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could…

Fix: 19.1.4 / 19.2.2+
Fix from $4,900 2026-08-12
GitLab HIGH 8.7
CVE-2026-15217

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

Fix: 19.0.6 / 19.1.4+
Fix from $4,900 2026-08-12
GitLab HIGH 8.7
CVE-2026-15216

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

Fix: 19.0.6 / 19.1.4+
Fix from $4,900 2026-08-12
Informix Dynamic Server HIGH 8.8
CVE-2026-13361

IBM Informix oninit sq_sgkprepare RCE via unchecked SQL Interface length field.

Fix: 15.0.1.14+
Fix from $4,900 2026-08-12
Security Verify Access HIGH 8.1
CVE-2026-13267

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.3.0
Fix from $4,900 2026-08-12
Security Verify Access HIGH 7.2
CVE-2026-12618

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.3.0
Fix from $4,900 2026-08-12
Security Verify Access HIGH 8.1
CVE-2026-12359

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.3.0
Fix from $4,900 2026-08-12
Security Verify Access HIGH 7.2
CVE-2026-12005

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.3.0
Fix from $4,900 2026-08-12
Security Verify Access HIGH 8.7
CVE-2026-12004

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.3.0
Fix from $4,900 2026-08-12
Security Verify Access HIGH 7.4
CVE-2026-11923

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: after 11.0.3.0
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-19311

Missing authorization in the Execute Monitor API in Amazon OpenSearch Alerting plugin might allow an authenticated remote user to read, modify, or de…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.1
CVE-2026-18952

Missing input validation in the threat intelligence feed parser in the OpenSearch Security Analytics plugin might allow an authenticated remote user …

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.5
CVE-2026-18678

When an operator adds an HTTPS control plane profile to kumactl without providing a CA certificate, kumactl disables TLS verification and sends API t…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.0
CVE-2026-18677

In Kong Mesh running in universal mode with a MeshIdentity whose SPIFFE ID path template derives from the dataplane's kuma.io/workload label, the XDS…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.1
CVE-2026-18676

The default kuma-cp configuration in Kong Mesh reveals the admin bootstrap token and signing keys to any webpage the operator visits while the contro…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-18675

The dataplane token validator in kuma-cp performs an unchecked Go type assertion on the JWT kid header. A token whose kid is a JSON number decodes as…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-18673

When kuma-dp is configured with the Envoy admin API on a Unix domain socket, which is the default, its readiness service on TCP port 9902 - bound to …

Patch available
Fix from $4,000 2026-08-12
GitLab HIGH 7.5
CVE-2026-7427

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under …

Fix: 19.0.6 / 19.1.4+
Fix from $4,900 2026-08-12
Unclassified HIGH 7.6
CVE-2026-73327

Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a craft…

Patch available
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.6
CVE-2026-73300

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru…

No fix yet
Fix from $5,750 2026-08-12
Unclassified CRITICAL 10.0
CVE-2026-73299

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .…

Patch available
Fix from $5,750 2026-08-12
Unclassified HIGH 8.7
CVE-2026-73298

The Microsoft Container Migration Solution Accelerator is a multi-service application that provides a multi-agent, AI-driven migration solution for m…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-69106

A low-privileged user may poison cached artifact metadata under specific conditions, potentially causing consumers to retrieve untrusted content.

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-49467

Pingvin Share X is a secure and easy self-hosted file sharing platform. A vulnerability in versions 1.5.0 through 1.18.0 allow an attacker to bypass …

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-44741

Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Versions prior to 2.3.6 and 1.7.18 have a SQL injection vulnerability in Pimcore's …

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing …

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-18713

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user …

Fix: after 7.6
Fix from $4,900 2026-08-12
I HIGH 8.8
CVE-2026-18669

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation as the result of a remote code execution vulnerability in the activation engine …

Fix: after 7.6
Fix from $4,900 2026-08-12
I MEDIUM 5.0
CVE-2026-18250

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to a ra…

Fix: after 7.6
Fix from $4,000 2026-08-12
I HIGH 8.3
CVE-2026-18235

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary Control Language commands due to insufficient input val…

Fix: after 7.6
Fix from $4,900 2026-08-12