Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.8
CVE-2026-70372

Koha's reports/bor_issues_top.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the qu…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-70371

Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-70370

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directl…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-70369

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parame…

No fix yet
Fix from $1,950 2026-08-04
Milo HIGH 7.5
CVE-2026-63252

In Eclipse Milo versions 0.6.0 through 1.1.4, UASC server transport handlers fail to release retained partial message chunks when a channel disconnec…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo MEDIUM 6.5
CVE-2026-63248

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An anonymous client can enable dia…

Fix: 1.1.5+
Fix from $1,600 2026-08-04
Milo HIGH 7.5
CVE-2026-62927

In Eclipse Milo versions 1.0.0 through 1.1.4, the Call service dispatches the original mixed batch to address-space handlers after calculating author…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 7.5
CVE-2026-61387

In Eclipse Milo versions 1.0.0 through 1.1.4, monitored-item quota accounting is not exception-safe: if item creation fails with an unchecked error, …

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 7.4
CVE-2026-60007

In Eclipse Milo versions 0.6.0 through 1.1.4, username-token processing returns distinguishable errors for invalid RSA PKCS#1 v1.5 padding and other …

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Milo HIGH 8.2
CVE-2026-58080

In Eclipse Milo versions 1.0.0 through 1.1.4, `OpcUaServerConfig.copy()` fails to preserve a configured `RoleMapper`. On servers that rely on role pe…

Fix: 1.1.5+
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-18809

Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-18806

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Im…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.8
CVE-2026-10710

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.8
CVE-2026-10709

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::Binar…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-66883

Improper Handling of Case Sensitivity vulnerability in Erlang Ecosystem Foundation oidcc_plug (Oidcc.Plug.Authorize module) renders the user agent se…

Patch available
Fix from $1,600 2026-08-04
Jetty CRITICAL 9.1
CVE-2026-10050

In Eclipse Jetty, the Digest authentication server-side component uses ISO-8859-1 to encode the password as bytes. This was done because the initi…

Fix: 9.4.63 / 10.0.31+
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-18772

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data Expansion.

Patch available
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-15721

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows S…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified HIGH 7.4
CVE-2026-14838

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resour…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-14804

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sen…

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14465

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Sess…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14219

URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-14202

Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Foot…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14194

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMAN…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14192

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc.…

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified HIGH 7.2
CVE-2026-67243

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative pri…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.5
CVE-2026-18759

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18755

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary …

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-18754

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private k…

Mitigation only
Fix from $2,300 2026-08-04