Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.5
CVE-2026-48113

Chisel is a TCP/UDP tunnel, transported over HTTP and secured via SSH. In versions prior to 1.11.5, authenticated clients can bypass --authfile ACL r…

Patch available
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-48063

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a mal…

Patch available
Fix from $2,300 2026-08-03
Unclassified MEDIUM 5.9
CVE-2026-48061

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. In versions prior to 2.22.0, an attacker can bypass the allowed hosts validati…

Patch available
Fix from $1,600 2026-08-03
Unclassified HIGH 7.8
CVE-2026-41447

FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vulnerability that allows local attackers to execute arbitrary code by placing a crafte…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-18737

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL fragments by supplying an un…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.0
CVE-2026-18736

Shlink contains a server-side request forgery vulnerability that allows authenticated API key holders to cause the server to issue arbitrary HTTP GET…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.8
CVE-2026-18733

A prompt injection vulnerability in the shell tool in Amazon Strands Agents Tools before 0.8.0 might allow remote actors to execute arbitrary operati…

Mitigation only
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18648

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDataColumn/FileDirectory.getFile…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.3
CVE-2026-18647

A security vulnerability has been detected in jina-ai reader up to 1574bfd380d249c86c82db4dace0d9c8fe17e2b1. This issue affects the function isValidT…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18646

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system/htmly.php of the component A…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18645

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /system/admin/admin.php of the co…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-69198

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. From 10.1.1 until 10.2.2, every special-use classificatio…

Patch available
Fix from $1,600 2026-08-03
Nifi CRITICAL 9.1
CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Unclassified HIGH 7.7
CVE-2026-69192

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.3.1, Address4 accepts an octet written with a…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69185

Socket.IO enables bidirectional and low-latency communication for every platform. Prior to 4.2.7, 3.4.5, and 3.3.6, a specially crafted Socket.IO pac…

Patch available
Fix from $1,950 2026-08-03
Nifi HIGH 7.5
CVE-2026-68981

Apache NiFi 1.5.0 through 2.10.0 support gzip-encoded HTTP requests for the application REST API using a Jersey encoding filter. The framework enforc…

Fix: 2.11.0+
Fix from $1,950 2026-08-03
Nifi CRITICAL 9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Unclassified HIGH 7.2
CVE-2026-67599

ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary comma…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.4
CVE-2026-67598

Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attacker…

No fix yet
Fix from $1,950 2026-08-03
Oaskit MEDIUM 6.1
CVE-2026-66296

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default H…

Fix: 0.14.1+
Fix from $1,600 2026-08-03
Unclassified HIGH 7.7
CVE-2026-62354

Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit propo…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-58139

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to e…

Patch available
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-48031

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secr…

Patch available
Fix from $2,300 2026-08-03
Unclassified HIGH 8.4
CVE-2026-47211

Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versio…

Patch available
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-18655

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.8
CVE-2026-18654

Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow m…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18644

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the compo…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.3
CVE-2026-18641

A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the fu…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-18632

A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-18631

A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr…

No fix yet
Fix from $1,600 2026-08-03