Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-5855

Contiki-NG's LwM2M TLV parser lwm2m_tlv_read() in os/services/lwm2m/lwm2m-tlv.c ignores its caller-supplied buffer length argument and reads up to si…

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.8
CVE-2026-5336

The DataPress (Dataverse Integration) WordPress plugin before 2.91 does not properly restrict access to its template rendering feature and exposes th…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-54717

Silverstripe CMS is an open source content management system. Prior to 6.2.1, page breadcrumbs in the CMS are vulnerable to cross-site scripting when…

Patch available
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-53984

Ground Station prior to 0.6.0 contains an unauthenticated database-destruction and arbitrary-data-injection vulnerability in the Socket.IO server's d…

Patch available
Fix from $2,300 2026-08-06
Unclassified HIGH 8.6
CVE-2026-53983

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital-source configuration path th…

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-50159

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulne…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-49391

Frappe is a full-stack web application framework. Prior to 16.19.0 and 15.109.0, Data Import does not escape imported column headers before rendering…

Patch available
Fix from $1,600 2026-08-06
Unclassified CRITICAL 9.4
CVE-2026-48088

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the route `POST /…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-48087

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the registration …

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-48086

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN pr…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-48085

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.1, a fully provision…

Patch available
Fix from $2,300 2026-08-06
Unclassified HIGH 7.4
CVE-2026-48084

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Versions prior to 1.0.2 don't throttle fa…

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-48083

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `/api/log` en…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 8.1
CVE-2026-48081

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, a TENANT_ADMIN ca…

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 8.0
CVE-2026-48080

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, the `GET /api/ten…

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 7.4
CVE-2026-48079

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.2, when a user navig…

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-48078

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the unauthenticat…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-48077

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.1.0, the GET handler a…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-48076

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. The new-client booking flow in versions 1…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-48075

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.5, the `add-to-tunne…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.8
CVE-2026-48071

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to version 1.0.4, the PIN-type chal…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 8.8
CVE-2026-48054

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to …

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-47765

Frappe is a full-stack web application framework. Prior to 15.110.0 and 16.20.0, the restore and bulk_restore endpoints do not apply the appropriate …

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 8.6
CVE-2026-47194

Frappe is a full-stack web application framework. Prior to 15.108.0 and 16.18.3, temporary magic login link generation can use an attacker-controlled…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.1
CVE-2026-47185

Frappe is a full-stack web application framework. Prior to 16.18.0, the Workspace Save API accepts a controlled workspace identifier from any authent…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-45573

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, when VAPID delivery …

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.0
CVE-2026-45415

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the /admin/csv_censu…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 8.5
CVE-2026-45414

Decidim is a participatory democracy framework. Prior to 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, JWT-backed API authentication is not bound to th…

Patch available
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-45378

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.32.0.rc2, the identity-documen…

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.1
CVE-2026-43632

llama.cpp builds b7492 through the latest b9060 contains a use-after-free vulnerability in llama-server affecting six tokenization endpoints (/tokeni…

No fix yet
Fix from $1,950 2026-08-06