Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-66340

The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login a…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-66098

The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootload…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-5917

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-29036

cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within c…

No fix yet
Fix from $4,900 2026-08-11
Chrome HIGH 8.8
CVE-2026-19560

Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H…

Fix: 151.0.7922.137+
Fix from $4,900 2026-08-11
Chrome HIGH 8.8
CVE-2026-19559

Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT…

Fix: 151.0.7922.137+
Fix from $4,900 2026-08-11
Chrome HIGH 7.5
CVE-2026-19558

Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to ex…

Fix: 151.0.7922.137+
Fix from $4,900 2026-08-11
Chrome HIGH 8.3
CVE-2026-19557

Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to pote…

Fix: 151.0.7922.137+
Fix from $4,900 2026-08-11
Chrome HIGH 8.8
CVE-2026-19556

Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML…

Fix: 151.0.7922.137+
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-18710

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to applica…

No fix yet
Fix from $4,000 2026-08-11
Httpclient CRITICAL 9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…

Fix: 5.6.4+
Fix from $5,750 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-66832

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query s…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.3
CVE-2026-66154

An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-66150

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-66149

Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66148

An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic…

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.4
CVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.1
CVE-2026-63177

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-63134

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-63133

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count…

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 8.8
CVE-2026-55676

Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.9
CVE-2026-48765

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from…

Patch available
Fix from $5,750 2026-08-11
Unclassified HIGH 8.2
CVE-2026-48763

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{b…

Patch available
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-48762

TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using …

Patch available
Fix from $4,000 2026-08-11
Unclassified HIGH 8.2
CVE-2026-19550

A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administratio…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-29035

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remot…

No fix yet
Fix from $4,000 2026-08-11
Snipe It MEDIUM 5.4
CVE-2026-19579

Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The ca…

Fix: 8.6.0+
Fix from $4,000 2026-08-11
Unclassified HIGH 8.4
CVE-2026-18634

An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-15606

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-14863

FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod…

No fix yet
Fix from $4,900 2026-08-11