Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-67867

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the Alarm/Conditions wrapper when pro…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-67866

Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the LockedStaMac_ProcessMsg_DeleteMon…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-19023

Untrusted pointer dereference in the render_bin_output function in the h5dump tool in HDF5 before 2.3.0 allows attackers to cause a denial of service…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-67863

In open62541 1.5.5, a server-side use-after-free exists in the local MonitoredItem callback path. The issue occurs when UA_Subscription_localPublish …

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-19026

H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_values[0] through cd_values[4] without validating that cd_values is non-NULL or t…

Patch available
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-19025

H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not validate that a chunked dataset's stored chunk-layout dimensionality matches its dat…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.2
CVE-2026-19024

NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.3.0 allows attackers to cause a denial of service via a dataset whose version 1 or 2 f…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71321

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint `/__nuxt_islan…

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-71320

Nuxt is an open-source web development framework for Vue.js. From 3.4.0 until 3.21.10 and 4.5.1, an attacker can inject a template key through /__nux…

Patch available
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.6
CVE-2026-71319

Nuxt is an open-source web development framework for Vue.js. Prior to 3.3.1, Nuxt DevTools (development mode only) exposes a bidirectional RPC channe…

Patch available
Fix from $2,300 2026-08-05
Unclassified HIGH 7.5
CVE-2026-67865

S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handling. This allows a remote attacker to cause a denial of service

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-67864

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the NodeManagement type-instantiation logic compon…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2025-63823

My Safetipin Android Application 5.2.1 contains Hardcoded credentials in the authentication module, which allows remote attackers to bypass authentic…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71316

Nuxt is an open-source web development framework for Vue.js. From 4.4.0 until 4.5.1, runtime cache:nuxt:payload entries for /<page>/_payload.json can…

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2025-63822

SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters t…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.2
CVE-2026-71315

Nuxt is an open-source web development framework for Vue.js. From 3.21.7 until 3.21.10 and 4.5.1, mixed-case routeRules keys can fail to match case-f…

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71314

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an unauthenticated attacker can use a server island …

Patch available
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.9
CVE-2026-71313

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From v1.51.0 until v1.75.0, the local b…

Patch available
Fix from $1,600 2026-08-05
Unclassified HIGH 8.0
CVE-2026-71312

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to v1.75.0, rclone interpolates r…

Patch available
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.4
CVE-2026-71311

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, a valid but nondefault…

Patch available
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.9
CVE-2026-71310

rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.0, the shared HTTP CONNEC…

Patch available
Fix from $1,600 2026-08-05
Unclassified HIGH 8.6
CVE-2026-71309

rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.40.0 until 1.75.0, rclone serve …

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 7.6
CVE-2026-34966

Gitea prior to 1.27.0 contains a server-side request forgery vulnerability that allows authenticated attackers to bypass SSRF protections by exploiti…

Patch available
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-18959

A flaw has been found in yushine InnoShop up to 0.8.2. Affected by this issue is the function FileManagerController::destroyFiles of the file innopac…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.1
CVE-2026-18411

The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. A…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.4
CVE-2026-17583

The affected Thermo Fisher Applied Biosystems Genetic Analyzers are vulnerable because .fsa/.hid output files can be edited. An attacker could tampe…

No fix yet
Fix from $1,950 2026-08-05
Enterprise Server HIGH 7.5
CVE-2026-15996

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause excessive CPU consumpt…

Fix: 3.17.16 / 3.18.10+
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-70617

Spacebar Server before commit dcfd910 contains a missing authorization vulnerability that allows any authenticated attacker to add themselves to arbi…

Patch available
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-70616

boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exhaust server file descrip…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-70615

boringproxy through 0.10.0 contains a newline injection vulnerability that allows authenticated low-privileged users with tunnel-creation permission …

No fix yet
Fix from $2,300 2026-08-05