Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.8
CVE-2026-18692

An issue in MongoDB Server's handling of timeseries bucket lifecycle could allow an authenticated user with write privileges to cause an internal ref…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-18691

An issue in MongoDB Server's intra-cluster connection setup could allow a party with suitable network access to influence which authentication mechan…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.1
CVE-2026-18690

An issue in MongoDB Server could allow an authenticated user with a limited database-scoped role to perform an action against protected system collec…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-18688

An issue in MongoDB Server's aggregation framework could allow an authenticated user to trigger an out-of-bounds memory read by providing a specially…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-18687

MongoDB Server's handling of a Queryable Encryption maintenance operation did not properly validate certain request parameters against the collection…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 8.8
CVE-2026-15426

The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to authorization by…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73219

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.17.0 until 2.72.0, a user with write access to a CVAT …

Patch available
Fix from $4,000 2026-08-11
Unclassified HIGH 7.7
CVE-2026-73218

Cursor is a code editor built for programming with AI. Prior to 3.0.0, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode, when Do…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.7
CVE-2026-73217

Cursor is a code editor built for programming with AI. Prior to 3.1.2, Cursor IDE for macOS allows an agent running in Auto-Run Sandbox mode to repla…

No fix yet
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-73216

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in src/server/ns_turn_server.c pre…

Patch available
Fix from $4,000 2026-08-11
Unclassified HIGH 7.1
CVE-2026-73215

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, turnports_allocate_even() in src/apps/relay/turn_ports.c marks …

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 8.2
CVE-2026-73214

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, dtls_server_input_handler() and create_new_connected_udp_socket…

Patch available
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-73213

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.16.0, addr_less_eq() in src/client/ns_turn_ioaddr.c uses a component-…

Patch available
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-73212

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.13.1, good_peer_addr() in src/server/ns_turn_server.c uses ioa_addr_i…

Patch available
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-73211

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac…

Patch available
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-73090

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd…

Patch available
Fix from $5,750 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72713

XAgent contains a path traversal vulnerability in the workspace file endpoint that allows self-registered or default-credential users to read arbitra…

Patch available
Fix from $4,900 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72712

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash the application by sending a …

Patch available
Fix from $4,000 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-71398

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

No fix yet
Fix from $5,750 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-71362

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…

No fix yet
Fix from $5,750 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-69113

Cap v0.3.1 contains a broken access control vulnerability in the POST /api/video/comment endpoint that allows authenticated users to post comments on…

Patch available
Fix from $4,000 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-69102

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica…

Patch available
Fix from $5,750 2026-08-11
Onedrive MEDIUM 6.7
CVE-2026-65680

Improper link resolution before file access ('link following') in Microsoft OneDrive allows an authorized attacker to elevate privileges locally.

Fix: 26.095.0519.0003+
Fix from $4,000 2026-08-11
Unclassified MEDIUM 5.5
CVE-2026-48790

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the user's Turso platform JWT to `s…

Patch available
Fix from $4,000 2026-08-11
Unclassified HIGH 8.2
CVE-2026-48771

ishankportfolio is a portfolio website. Prior to version 1.0.1, contact form submissions could potentially be exposed due to improperly secured clien…

No fix yet
Fix from $4,900 2026-08-11
Unclassified HIGH 7.6
CVE-2026-48767

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to obtain a live Google Sheets OAuth ac…

Patch available
Fix from $4,900 2026-08-11
Unclassified HIGH 7.1
CVE-2026-48494

TypeBot is a chatbot builder tool. In version 3.16.1, an authenticated user who has read access to any typebot can resume a WhatsApp preview webhook …

Patch available
Fix from $4,900 2026-08-11
Lightroom HIGH 7.7
CVE-2026-48447

Lightroom Classic is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current…

Fix: 15.5+
Fix from $4,900 2026-08-11
Lightroom HIGH 8.6
CVE-2026-48441

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to a…

Fix: 15.5+
Fix from $4,900 2026-08-11
Unclassified HIGH 7.5
CVE-2026-48416

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage thi…

No fix yet
Fix from $4,900 2026-08-11