Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-73244

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/sr…

Patch available
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-73243

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView i…

Patch available
Fix from $4,000 2026-08-11
Unclassified HIGH 8.3
CVE-2026-73242

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptM…

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 8.3
CVE-2026-73241

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an a…

Patch available
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-73235

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp b…

Patch available
Fix from $4,000 2026-08-11
Unclassified HIGH 7.8
CVE-2026-73234

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp co…

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 8.5
CVE-2026-73233

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui…

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-73232

ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because th…

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 7.8
CVE-2026-73231

Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.t…

Patch available
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-73230

Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte len…

Patch available
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-73034

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s…

Patch available
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-73032

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou…

Patch available
Fix from $5,750 2026-08-11
Unclassified HIGH 8.7
CVE-2026-73031

telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browser…

Patch available
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71845

A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.0
CVE-2026-71475

A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-71474

A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-71468

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-71467

A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ…

No fix yet
Fix from $4,900 2026-08-11
Edge Chromium MEDIUM 5.4
CVE-2026-70339

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

Fix: 151.0.4129.78+
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-66146

Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker …

No fix yet
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.7
CVE-2026-48813

Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralizati…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-48804

python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` me…

Patch available
Fix from $4,900 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 8.1
CVE-2026-19091

The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due t…

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18844

The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These command…

No fix yet
Fix from $4,900 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-16230

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-13457

The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.3
CVE-2024-14042

A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s…

Patch available
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73228

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py …

Patch available
Fix from $4,000 2026-08-11