Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-7327

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 all…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-7326

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures a…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.9
CVE-2026-70606

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0,…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.9
CVE-2026-70605

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.4
CVE-2026-70604

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0,…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.0
CVE-2026-70603

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.6
CVE-2026-70602

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-70601

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-b…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.9
CVE-2026-70599

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.3
CVE-2026-70597

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Answer CRITICAL 9.1
CVE-2026-60053

Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u…

Fix: 2.0.2+
Fix from $2,300 2026-08-05
Answer HIGH 7.5
CVE-2026-60023

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Answer MEDIUM 6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Answer MEDIUM 6.5
CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar…

Fix: 2.0.2+
Fix from $1,600 2026-08-05
Answer HIGH 7.5
CVE-2026-48911

Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authoriza…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-53992

ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitra…

Patch available
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-49331

A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identit…

No fix yet
Fix from $1,600 2026-08-05
Answer HIGH 7.5
CVE-2026-48834

Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate…

Fix: 2.0.2+
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-39924

Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full acco…

Patch available
Fix from $1,600 2026-08-05
Unclassified HIGH 8.1
CVE-2026-39923

Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password rese…

Patch available
Fix from $1,950 2026-08-05
Maximo Application Suite MEDIUM 5.3
CVE-2026-18531

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signin…

Fix: 9.0.28 / 9.1.20+
Fix from $1,600 2026-08-05
Build Of Keycloak CRITICAL 9.8
CVE-2026-16442

A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca…

Fix: 26.4.14 / 26.6.5+
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.4
CVE-2026-15587

Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to…

Mitigation only
Fix from $2,300 2026-08-05
Build Of Keycloak HIGH 8.8
CVE-2026-15572

A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restri…

Fix: 26.4.14 / 26.6.5+
Fix from $1,950 2026-08-05
Qradar Security Information And Event Manager HIGH 8.8
CVE-2026-13477

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c…

Mitigation only
Fix from $1,950 2026-08-05
Business Automation Insights MEDIUM 5.3
CVE-2026-12762

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in man…

No fix yet
Fix from $1,600 2026-08-05
Qradar Security Information And Event Manager CRITICAL 9.8
CVE-2026-10025

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.5
CVE-2026-54876

Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response tha…

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-17613

Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files o…

No fix yet
Fix from $1,950 2026-08-05
Build Of Keycloak HIGH 8.1
CVE-2026-16102

A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy f…

Fix: 26.4.14 / 26.6.5+
Fix from $1,950 2026-08-05