Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.4
CVE-2026-50236

An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without …

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.8
CVE-2026-13739

A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar…

No fix yet
Fix from $1,950 2026-08-11
Unclassified CRITICAL 9.2
CVE-2026-13738

CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.2
CVE-2026-13737

CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance …

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function…

No fix yet
Fix from $2,300 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73162

Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/d…

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.0
CVE-2026-33922

A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an i…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.2
CVE-2026-33921

The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73161

Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function…

Patch available
Fix from $1,600 2026-08-11
Unclassified HIGH 8.7
CVE-2026-73160

Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation rou…

Patch available
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73159

Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() …

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-73158

Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are…

Patch available
Fix from $1,600 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72694

A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can expl…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.8
CVE-2026-72693

`openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `k…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-71218

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-control…

Patch available
Fix from $1,600 2026-08-11
Unclassified HIGH 7.5
CVE-2026-71217

A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameter…

Patch available
Fix from $1,950 2026-08-11
Unclassified HIGH 7.5
CVE-2026-15567

A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-contro…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.5
CVE-2026-15565

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class th…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.4
CVE-2026-15563

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI l…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.5
CVE-2026-15562

A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-r…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.5
CVE-2026-15561

A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthentica…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.1
CVE-2026-15560

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.1
CVE-2026-15556

A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow a…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.8
CVE-2026-15555

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River u…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.4
CVE-2026-15554

the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut…

No fix yet
Fix from $1,950 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-10579

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe…

No fix yet
Fix from $2,300 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73156

Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice name…

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73155

Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users …

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-73140

Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal commen…

Patch available
Fix from $1,600 2026-08-11
Unclassified HIGH 7.3
CVE-2026-19418

The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving t…

Patch available
Fix from $1,950 2026-08-11