Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-70634

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compr…

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-70633

TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator tha…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 7.8
CVE-2026-70632

FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decod…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.5
CVE-2026-70631

FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in li…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.5
CVE-2026-70630

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (li…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.5
CVE-2026-70629

FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.8
CVE-2026-70628

FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsu…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-70559

Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-70558

Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-70557

diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those …

No fix yet
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67689

SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated …

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-67688

ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.8
CVE-2026-67687

Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleContro…

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-67622

Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac…

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 7.6
CVE-2026-67621

Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.3
CVE-2026-67434

PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer …

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-67422

pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret…

Patch available
Fix from $1,950 2026-08-06
macOS CRITICAL 9.8
CVE-2026-65400 KEV

An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2…

Fix: 14.8.9 / 15.7.9+
Fix from $2,300 2026-08-06
Unclassified MEDIUM 5.9
CVE-2026-64677

Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requeste…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 8.1
CVE-2026-64665

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that …

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-64663

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-64662

Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-64654

GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-64653

GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent …

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 7.2
CVE-2026-63725

sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-con…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.6
CVE-2026-63637

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strin…

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 8.8
CVE-2026-62857

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-61632

PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vul…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 8.1
CVE-2026-5857

Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte…

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-5856

Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the ca…

Patch available
Fix from $1,950 2026-08-06