Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Windows 10 1809 HIGH 7.8
CVE-2026-56174

Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.

Fix: 10.0.17763.9115 / 10.0.19044.7663+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 7.8
CVE-2026-54984

Heap-based buffer overflow in Windows Imaging Component allows an unauthorized attacker to execute code locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Python HIGH 7.8
CVE-2026-54981

Inclusion of functionality from untrusted control sphere in Visual Studio Code - Python extension allows an unauthorized attacker to bypass a securit…

No fix yet
Fix from $4,900 2026-08-11
Defender For Endpoint MEDIUM 5.5
CVE-2026-54123

Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information l…

Fix: 101.26042.0020+
Fix from $4,000 2026-08-11
Windows 10 1607 HIGH 7.5
CVE-2026-54113

Allocation of resources without limits or throttling in Windows Kernel allows an unauthorized attacker to deny service over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Azure Kubernetes Service CRITICAL 9.4
CVE-2026-50516

Missing authentication for critical function in Microsoft Azure Kubernetes Service allows an unauthorized attacker to elevate privileges over a netwo…

No fix yet
Fix from $5,750 2026-08-11
Windows 10 1607 HIGH 7.0
CVE-2026-50472

Heap-based buffer overflow in Windows LUAFV allows an authorized attacker to elevate privileges locally.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Windows 10 1607 HIGH 8.8
CVE-2026-49179

Improper neutralization of special elements used in a command ('command injection') in Windows Active Directory allows an unauthorized attacker to ex…

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $4,900 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-48483

TypeBot is a chatbot builder tool. Prior to version 3.17.0, Typebot's WhatsApp status forwarding feature stores a workspace-configured webhook forwar…

Patch available
Fix from $4,000 2026-08-11
C2pa MEDIUM 5.5
CVE-2026-48446

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lea…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.2
CVE-2026-48445

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.2
CVE-2026-48444

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.2
CVE-2026-48443

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa HIGH 7.1
CVE-2026-48442

CAI Content Credentials is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could res…

Fix: 0.12.1 / 0.27.6+
Fix from $4,900 2026-08-11
Coldfusion HIGH 8.1
CVE-2026-48440

ColdFusion is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user…

No fix yet
Fix from $4,900 2026-08-11
C2pa HIGH 7.5
CVE-2026-48439

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…

Fix: 0.12.1 / 0.27.6+
Fix from $4,900 2026-08-11
C2pa HIGH 7.5
CVE-2026-48438

CAI Content Credentials is affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker co…

Fix: 0.12.1 / 0.27.6+
Fix from $4,900 2026-08-11
C2pa MEDIUM 5.5
CVE-2026-48437

CAI Content Credentials is affected by an Improper Certificate Validation vulnerability that could result in a Security feature bypass. An attacker c…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.5
CVE-2026-48436

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could l…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.2
CVE-2026-48435

CAI Content Credentials is affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service.…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.2
CVE-2026-48434

CAI Content Credentials is affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attack…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
C2pa MEDIUM 6.2
CVE-2026-48387

CAI Content Credentials is affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An atta…

Fix: 0.12.1 / 0.27.6+
Fix from $4,000 2026-08-11
Coldfusion HIGH 7.5
CVE-2026-48386

ColdFusion is affected by a Use of a Broken or Risky Cryptographic Algorithm vulnerability that could lead to disclosure of sensitive memory. An atta…

No fix yet
Fix from $4,900 2026-08-11
Coldfusion HIGH 7.7
CVE-2026-48385

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…

No fix yet
Fix from $4,900 2026-08-11
Coldfusion MEDIUM 5.4
CVE-2026-48376

is affected by an Improper Encoding or Escaping of Output vulnerability that could result in a Security feature bypass. A low-privileged attacker cou…

No fix yet
Fix from $4,000 2026-08-11
Coldfusion MEDIUM 6.5
CVE-2026-48375

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service. A low-privileged attacker c…

No fix yet
Fix from $4,000 2026-08-11
Coldfusion CRITICAL 10.0
CVE-2026-48362

ColdFusion is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could resu…

No fix yet
Fix from $5,750 2026-08-11
Unclassified HIGH 7.1
CVE-2026-47704

TypeBot is a chatbot builder tool. Prior to version 3.17.0, an authenticated user who has read access to any typebot can resume a waiting webhook ses…

Patch available
Fix from $4,900 2026-08-11
Azure Monitor Agent HIGH 7.2
CVE-2026-47299

Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate p…

Fix: 1.43+
Fix from $4,900 2026-08-11
Visual Studio Code MEDIUM 6.5
CVE-2026-47285

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unauthorized attacker to disclose…

Fix: 1.132.1+
Fix from $4,000 2026-08-11