Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Airflow MEDIUM 6.5
CVE-2026-65017

Apache Airflow's Config API did not mask team-scoped sensitive configuration values in multi-team deployments. When an administrator has enabled mult…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.3
CVE-2026-64639

Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute …

No fix yet
Fix from $5,750 2026-08-12
Airflow MEDIUM 6.5
CVE-2026-59244

Apache Airflow's secrets masker did not mask `var.json` Variable values whose value is a dict in the Rendered Templates UI — the dict value failed an…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow MEDIUM 5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload through `BaseXCom.deserialize_v…

Fix: 3.3.1+
Fix from $4,000 2026-08-12
Airflow HIGH 8.8
CVE-2026-58076

Apache Airflow's serialization layer reconstructed exception nodes by calling `import_string()` on a class name taken from the serialized blob and in…

Fix: 3.3.1+
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.5
CVE-2026-19548

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker (ld), a component of binutils…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.7
CVE-2026-15803

In Eclipse RDF4J, several XML parser entry points do not fully restrict XML External Entity (XXE) processing when parsing untrusted XML-based RDF dat…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.1
CVE-2026-73432

Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization functionality. Remote instanc…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 8.8
CVE-2026-73431

Vulnerability-Lookup contains an authentication weakness in its account activation and password-recovery mechanism. Activation and recovery links w…

Patch available
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73405

An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server-Sent Events (SSE) strea…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-73374

A stored cross-site scripting (XSS) vulnerability existed in Vulnerability-Lookup in the render_tag_badges Jinja filter used to display reference tag…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 7.1
CVE-2026-73291

Seerr is an open-source media request and discovery manager for Jellyfin, Plex, and Emby. Prior to version 3.4.0, Seerr's ImageProxy in server/lib/im…

Patch available
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-73290

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, an anonymous ListObjectVersions request in rustfs/src/storage/ac…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-73289

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS evaluates the ForAllValues: and ForAnyValue: set qualifie…

Patch available
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-73288

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-rc.1, RustFS Object Lock enforcement in crates/ecstore/src/bucket/object_…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-73287

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriver::mkd in crates/protocols/s…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-73286

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS get_condition_values folds attacker-controlled request he…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2026-73285

RustFS is a distributed object storage system built in Rust. From 1.0.0-alpha.64 until 1.0.0-rc.1, RustFS external OPA authorization enabled by RUSTF…

Patch available
Fix from $4,900 2026-08-12
Unclassified HIGH 8.8
CVE-2026-73284

RustFS is a distributed object storage system built in Rust. RustFS AddServiceAccount in rustfs/src/admin/handlers/service_account.rs accepts an atta…

Patch available
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-73265

RustFS is a distributed object storage system built in Rust. RustFS authorizes explicit versionId reads in GetObject, CopyObject sources, and UploadP…

Patch available
Fix from $4,000 2026-08-12
Unclassified HIGH 7.6
CVE-2026-73264

Prowler is a cloud security platform. Prior to 5.33.1, an authenticated user with Lighthouse provider configuration access could supply an unvalidate…

Patch available
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73263

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp au…

Patch available
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-73262

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.py inserted finding.resource_…

Patch available
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-68760

An unauthenticated user may bypass authentication under specific cache conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2026-68757

A user with access to a valid SAML response may impersonate another user under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.6
CVE-2026-68756

A party with write access to stored session data may affect JFrog Artifactory under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-68754

A repository publisher without delete permission may modify protected package content under specific conditions.

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-68753

An unauthenticated user may access restricted Artifactory content when a credentialed remote repository is configured in a specific way.

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.2
CVE-2026-68752

A Project Resource Manager may gain broader administrative privileges under specific conditions.

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.3
CVE-2026-67287

Joomla Extension - joomshaper.com - Unauthenticated comment creation in SP Page Builder < 6.8.0 - An unauthenticated attacker can create comments on …

No fix yet
Fix from $4,000 2026-08-12