Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-64630

A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-63456

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-63455

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.5
CVE-2026-58073

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credenti…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.0
CVE-2026-58072

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

Mitigation only
Fix from $2,300 2026-08-04
Unclassified HIGH 8.2
CVE-2026-58071

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator dur…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.7
CVE-2026-58067

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-56848

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resu…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.7
CVE-2026-48121

@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js CheckpointSaver implementation that uses MongoDB for storage. Versions 1.3.0 and belo…

Patch available
Fix from $1,600 2026-08-04
Unclassified HIGH 8.8
CVE-2026-18787

A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affected element is the function remove_rule of the file /usr/share/gl-ngx/oui-rpc.…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-18785

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Client_getRemoteDataTypes of the…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-18784

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute of the file src/client/ua_cli…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18775

A vulnerability has been found in NousResearch hermes-agent up to 0.16.0. This vulnerability affects the function browser_snapshot of the file tools/…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18774

A flaw has been found in NousResearch hermes-agent up to 0.16.0. This affects the function save_url_image of the file agent/image_gen_provider.py of …

No fix yet
Fix from $1,600 2026-08-04
Django HIGH 8.8
CVE-2026-15307

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango spatial lookups optimistically parse the right-hand-side value as…

Fix: 5.2.17 / 6.0.8+
Fix from $1,950 2026-08-04
Django MEDIUM 6.1
CVE-2026-15920

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.contrib.admin.utils.display_for_field()` renders `URLField` values …

Fix: 5.2.17 / 6.0.8+
Fix from $1,600 2026-08-04
Django MEDIUM 5.3
CVE-2026-15830

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeometry` is subject to a potentia…

Fix: 5.2.17 / 6.0.8+
Fix from $1,600 2026-08-04
Django MEDIUM 5.3
CVE-2026-15337

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()` is subject to a potential d…

Fix: 5.2.17 / 6.0.8+
Fix from $1,600 2026-08-04
Tapo P110 Firmware HIGH 7.5
CVE-2026-15314

Tapo P110 v1 smart Wi-Fi Plug contains an improper boundary validation vulnerability in the handling of authenticated HTTP request bodies due to insu…

Fix: 1.1.4+
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2025-29296

H3C Magic BE18000 V200R007, H3C NX400 V100R015, H3C Magic NX30 Pro V100R0011, H3C Magic R3010 V100R009, H3C Magic NX15 V100R017, H3C Magic R1510 V100…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.4
CVE-2026-69254

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriptCode() accepted caller-prov…

Patch available
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.0
CVE-2026-69253

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1.3, several custom-tool compo…

Patch available
Fix from $2,300 2026-08-04
Unclassified HIGH 7.2
CVE-2026-69252

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the /api/v1/files route was protected only b…

Patch available
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-69110

OpenCode Studio before 2.4.4 contains a missing authentication vulnerability that allows unauthenticated remote attackers to read arbitrary files wit…

Patch available
Fix from $2,300 2026-08-04
Unclassified HIGH 8.8
CVE-2026-69100

LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes u…

Patch available
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-69098

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to …

Mitigation only
Fix from $2,300 2026-08-04
Sm6225p Firmware HIGH 7.6
CVE-2026-25292

Memory Corruption when processing untrusted user input in the fastboot command handler for audio framework configuration.

Patch available
Fix from $1,950 2026-08-04
Sm7550p Firmware CRITICAL 9.6
CVE-2026-25289

Memory Corruption when processing Device Capability Extended attributes in certain NAN Service Discovery Frames with invalid length values.

No fix yet
Fix from $2,300 2026-08-04
Qam8295p Firmware HIGH 7.8
CVE-2026-24083

Memory Corruption while processing IOCTL device driver requests with invalid arguments.

Patch available
Fix from $1,950 2026-08-04
Orne Firmware HIGH 7.4
CVE-2026-25288

Transient DOS when processing a short target wake time channel usage response frame with insufficient packet size.

No fix yet
Fix from $1,950 2026-08-04