Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-48159

use-reducer-async is a React useReducer with async actions. Between 2026-05-18 16:29:52 and 2026-05-19 15:26:07, the default branch contained malicio…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-16626

Improper restriction of XML external entity reference vulnerability (unauthenticated) in Jaspersoft JasperReports Server. This issue affects JasperR…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 8.6
CVE-2026-10754

Pega Platform versions 8.5.0 through 25.1.2 are affected by an improper validation of cryptographic signatures that may allow an attacker to bypass s…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.1
CVE-2026-72731

Discourse is an open-source discussion platform. From 2026.1.0-latest until 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, anyone able to run a…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.7
CVE-2026-72730

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, the Rich Text Editor rendered a chat-transcript…

Patch available
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-72728

Discourse is an open-source discussion platform. Prior to 2026.1.7, an authenticated user could submit specially formed URLs that bypassed the Onebox…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-71577

A flaw was found in multicluster-global-hub. During a ManagedClusterMigration, the system incorrectly grants all managed hubs read access to a shared…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.5
CVE-2026-71576

A flaw was found in multicluster-global-hub. The manager component improperly validates the source identity of incoming CloudEvents on Kafka status t…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.5
CVE-2026-63623

A flaw was found in libvirt. During storage volume clone or convert operations, newly created volume images were temporarily world-readable. This was…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-56619

HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected XSS) due to insufficient validation and output encoding of user-controll…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72726

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on privat…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-72725

Discourse is an open-source discussion platform. Prior to 2026.1.6, the staff action log model rendered unescaped previous and new value fields that …

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-72723

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.anonymous_default_navigation_men…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-72721

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChecker.is_blocked? compares host…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.4
CVE-2026-72720

Discourse is an open-source discussion platform. Prior to 2026.1.7, 2026.6.2, 2026.7.1, and 2026.8.0-latest.1, Discourse has HTML injection in Pretty…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.7
CVE-2026-72719

Chatwoot is a customer engagement suite. Prior to 4.9.0, Chatwoot allowed authenticated account administrators to transfer Portals, Automation Rules,…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 7.0
CVE-2026-72718

goose is general-purpose AI agent that runs on your machine. Prior to 1.44.0, the `goose review` command runs the system `git` executable to gather t…

Patch available
Fix from $1,950 2026-08-10
Unclassified HIGH 8.8
CVE-2026-66738

SPIP before 4.4.18 contains a code injection vulnerability in SQLite-backed installations. The navigation menu endpoint improperly handles array-type…

No fix yet
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-48158

use-context-selector is a React useContextSelector hook in userland Between 2026-05-18 15:57:18 and 2026-05-19 15:24:34, the default branch contained…

No fix yet
Fix from $2,300 2026-08-10
Unclassified HIGH 7.5
CVE-2026-48048

XWiki Platform is a generic wiki platform. XWiki discovered that the patch for GHSA-5cf8-vrr8-8hjm was insufficient. Starting with version 6.2.1 and …

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.3
CVE-2026-47754

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.x through 2.19.1 and all 1.x versions conta…

Patch available
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-72761

The webhook URL validator in `website/notifications/webhooks.py` uses `ip.is_global` to reject non-public addresses after DNS resolution. IPv6 transi…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-72760

Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. When an authenticated user follo…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.9
CVE-2026-72759

In affected versions of MISP cti-transmute, the conversion-history details endpoint performs an incomplete authorization check. When a history record…

Patch available
Fix from $1,600 2026-08-10
Unclassified HIGH 8.6
CVE-2026-19433

Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated us…

Patch available
Fix from $1,950 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-18412

OpenCart extensions are uploaded as zip files with .ocmod.zip extensions. Upon installation, the OpenCart v4.2.0.0 extension installer extracts these…

No fix yet
Fix from $2,300 2026-08-10
Unclassified MEDIUM 5.1
CVE-2026-72751

CTI-Transmute is affected by a stored cross-site scripting (XSS) vulnerability in the conversion graph used to visualise converted MISP and STIX cont…

Patch available
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.8
CVE-2026-71959

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /collect request body, allowing…

Patch available
Fix from $1,600 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-63106

ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection vulnerability in the product listing API where the rating parameter from the pr…

No fix yet
Fix from $2,300 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-63105

ReadyEcommerce before 4.5.2 contains a stored cross-site scripting (XSS) vulnerability that allows authenticated customers to inject malicious HTML p…

No fix yet
Fix from $1,600 2026-08-10