Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-18907

Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in t…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-18897

A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOne…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.3
CVE-2026-18896

A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/ch…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-18895

A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performin…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.3
CVE-2026-18859

A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.7
CVE-2026-46334

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerabilit…

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 8.7
CVE-2026-45809

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions prior to 3.6.6 and 4.0.0-rc1 contain a denial of service vulnerabilit…

Patch available
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-45705

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the find_line_delimiter() function i…

Patch available
Fix from $1,600 2026-08-05
Unclassified HIGH 7.3
CVE-2026-18854

A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClas…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-18853

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the componen…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-45537

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concate…

Patch available
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18818

A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-70620

Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to pr…

Patch available
Fix from $1,600 2026-08-04
Unclassified HIGH 8.8
CVE-2026-70619

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embeddi…

Patch available
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.7
CVE-2026-70594

Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have all…

Patch available
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.6
CVE-2026-70593

Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside …

Patch available
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.5
CVE-2026-70592

Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the fil…

Patch available
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67862

open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attack…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67860

open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backe…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67861

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67859

Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67858

Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the M…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67856

An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(S…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67855

open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This all…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-52370

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in th…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-51144

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67857

open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-45103

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses…

Patch available
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-45100

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in …

Patch available
Fix from $2,300 2026-08-04
Unclassified HIGH 8.7
CVE-2026-45084

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the …

No fix yet
Fix from $1,950 2026-08-04