Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-19518

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation.

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-19517

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlot…

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-19391

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. Th…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.5
CVE-2026-16053

Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exch…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-8158

The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.1
CVE-2026-6505

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-6181

The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.7
CVE-2026-5304

An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.7
CVE-2026-5303

The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.2
CVE-2026-4757

A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an…

No fix yet
Fix from $1,600 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-19516

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the…

No fix yet
Fix from $2,300 2026-08-11
Crafty Controller CRITICAL 9.1
CVE-2026-13716

Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path…

Fix: 4.10.8+
Fix from $2,300 2026-08-11
Unclassified MEDIUM 5.2
CVE-2026-12052

The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size respons…

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-11894

The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-own…

Patch available
Fix from $1,600 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-19425

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb…

No fix yet
Fix from $2,300 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-16974

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-11893

The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates t…

Patch available
Fix from $1,600 2026-08-11
Unclassified HIGH 8.4
CVE-2026-8917

Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a spe…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-24330

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.5
CVE-2026-19424

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66779

Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-66778

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66777

SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66776

SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.9
CVE-2026-66773

A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-66771

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user …

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.3
CVE-2026-66770

Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.9
CVE-2026-66763

SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-66760

SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from …

No fix yet
Fix from $1,600 2026-08-11