Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.4
CVE-2026-48551

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cross-site request forgery protection bypass via a self-supplied double-submit cook…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-48550

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to reflected cross-site scripting in cmd.cgi via the NagFormId parameter. An u…

No fix yet
Fix from $4,000 2026-08-12
I CRITICAL 9.8
CVE-2026-18847

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

No fix yet
Fix from $5,750 2026-08-12
I HIGH 8.8
CVE-2026-18683

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to privilege escalation via Navigator for i. An authenticated user could elevate privileges to a root user…

No fix yet
Fix from $4,900 2026-08-12
Websphere Application Server HIGH 8.1
CVE-2026-18499

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to a privilege escalation when using Liberty collectives.

Fix: 26.0.0.9+
Fix from $4,900 2026-08-12
I HIGH 7.1
CVE-2026-17094

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and manipulate files due to a path traversal…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.1
CVE-2026-18098

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information and compromise system integrity due to an XM…

No fix yet
Fix from $4,900 2026-08-12
I HIGH 8.3
CVE-2026-17095

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to unsafe reflection.

No fix yet
Fix from $4,900 2026-08-12
I MEDIUM 5.4
CVE-2026-16694

IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScr…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.8
CVE-2026-73325

Fujitsu Research's OneCompression library 1.2.0 contains an unsafe deserialization vulnerability that allows attackers to execute arbitrary code by s…

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73294

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controll…

Patch available
Fix from $5,750 2026-08-12
Unclassified HIGH 8.8
CVE-2026-73293

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.19 and from 2.19.0-alpha3 until 2.19.5-beta5, ProjectMiddleware and GetProj…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 8.3
CVE-2026-73292

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.21, the /api/users/{id}/password endpoint accepts a cross-site request using…

Patch available
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.9
CVE-2026-69107

An unauthenticated user may access restricted artifacts in JFrog Artifactory under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-69105

An unauthenticated attacker may cause untrusted package content to be cached under specific conditions, potentially affecting artifact integrity and …

No fix yet
Fix from $4,900 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68971

Apache Airflow's asset materialization endpoint (`POST /api/v2/assets/{asset_id}/materialize`) and the XCom result check on `wait_dag_run_until_finis…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68969

Apache Airflow wrote Variable values and Connection `extra` contents to the audit log in cleartext when they were submitted through the bulk endpoint…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 7.5
CVE-2026-68968

Apache Airflow's Backfill API authorized a request against a Dag id supplied by the caller whenever the `backfill_id` path segment failed to parse. T…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-68970

Apache Airflow's Task SDK did not mask the contents of a Variable whose JSON value is a list, so secrets stored in that shape appeared in cleartext i…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Unclassified HIGH 7.2
CVE-2026-68759

A holder of a valid integration credential may impersonate other users under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Airflow HIGH 8.8
CVE-2026-67587

Apache Airflow's Task SDK rebuilt a `Callback` object from serialized data by re-running its constructor, which imports the module named by the store…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-68758

A low-privileged authenticated user may access restricted support information under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Airflow MEDIUM 5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's scope. The guard meant to p…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 7.3
CVE-2026-67260

Apache Airflow 3.3.0 moved human-in-the-loop tasks from the triggerer to a new `awaiting_input` task state swept by the scheduler. That sweep deseria…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-66384

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.7
CVE-2026-66016

Under specific self-hosted Helm configurations, generated TLS private keys may be retained in rendered manifests accessible to highly privileged loca…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.8
CVE-2026-65941

In WhatsUp Gold versions released before 2026.0.2, an unauthenticated remote attacker with network access to the affected service can execute arbitra…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible location on the host server.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arbitrary file extension within …

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.0
CVE-2026-65937

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

No fix yet
Fix from $4,900 2026-08-12