Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-72910

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 7.1
CVE-2026-72909

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions pa…

Patch available
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72908

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72907

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py …

Patch available
Fix from $1,600 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-72904

Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in …

Patch available
Fix from $2,300 2026-08-10
Unclassified HIGH 8.1
CVE-2026-72903

Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal file…

Patch available
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72743

SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders T…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 7.8
CVE-2026-63622

A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera…

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48160

react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18982

A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to es…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18951

A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` manageme…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18950

A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The sy…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18949

A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit …

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-18948

A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'd…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.5
CVE-2026-18947

A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a spec…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-18942

A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by …

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 7.7
CVE-2026-18941

A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no securi…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.6
CVE-2026-18621

A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a maliciou…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.1
CVE-2026-18620

A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServic…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.5
CVE-2026-18618

A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service …

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-18617

A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.5
CVE-2026-18611

A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such …

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2026-18608

A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privile…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the …

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.0
CVE-2026-15581

A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and dire…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.1
CVE-2026-15467

A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by …

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-14450

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP head…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.8
CVE-2026-13717

A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.5
CVE-2026-11810

The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.9
CVE-2026-72902

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands o…

Patch available
Fix from $2,300 2026-08-10