Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.2
CVE-2026-70478

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.5
CVE-2026-70477

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using …

Patch available
Fix from $2,300 2026-08-04
Unclassified HIGH 8.3
CVE-2026-70476

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in pa…

Patch available
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70475

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in p…

Patch available
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-48154

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA…

Patch available
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-47682

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write acce…

Patch available
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18810

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulat…

No fix yet
Fix from $1,950 2026-08-04
Kiro Cli HIGH 7.8
CVE-2026-18657

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code…

Fix: 2.10.0+
Fix from $1,950 2026-08-04
Kiro Ide HIGH 7.8
CVE-2026-18656

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary cod…

Fix: 1.0.228+
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-16793

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) …

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.1
CVE-2026-16792

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.6
CVE-2026-70474

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credenti…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.3
CVE-2026-70473

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-histor…

Patch available
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70472

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpo…

Patch available
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-70471

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the co…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-69704

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET pa…

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-69703

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated att…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-69702

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server …

No fix yet
Fix from $1,600 2026-08-04
Openshift Container Platform HIGH 7.1
CVE-2026-68743

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining …

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.0
CVE-2026-66300

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitr…

Patch available
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-49435

Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially cr…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified HIGH 8.4
CVE-2026-47781

PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plu…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.4
CVE-2026-47764

pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.1
CVE-2026-13229

Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-0163

In multiple functions of vpu_ioctl.c, there is a possible use after free due to a use after free. This could lead to remote escalation of privilege w…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2017-20242

Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted pa…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2017-20241

Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted pac…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.5
CVE-2026-70470

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in pa…

Patch available
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.4
CVE-2026-69264

Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that…

Patch available
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-47763

pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local sta…

No fix yet
Fix from $1,600 2026-08-04