Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.6
CVE-2026-68587

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and get…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.6
CVE-2026-68586

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.8
CVE-2026-68585

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.6
CVE-2026-68584

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM,…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.2
CVE-2026-67608

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_au…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-64827

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.8
CVE-2026-18642

Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. Thi…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18601

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.8
CVE-2026-18600

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr…

No fix yet
Fix from $1,950 2026-08-03
Net\ CRITICAL 9.8
CVE-2026-18108

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte…

Fix: 0.86+
Fix from $2,300 2026-08-03
Net\ HIGH 8.1
CVE-2026-18092

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity wi…

Fix: 0.86+
Fix from $1,950 2026-08-03
Net\ HIGH 7.5
CVE-2026-18089

Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_…

Fix: 0.86+
Fix from $1,950 2026-08-03
Icontrol MEDIUM 6.5
CVE-2026-56609

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TL…

No fix yet
Fix from $1,600 2026-08-03
Icontrol MEDIUM 5.3
CVE-2026-56608

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-2346

Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affe…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.0
CVE-2026-18599

A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/lo…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.8
CVE-2026-18598

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-h…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-18574

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an una…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.8
CVE-2026-69082

CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoi…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-69079

CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a …

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.8
CVE-2026-69078

CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI …

Patch available
Fix from $1,950 2026-08-03
Openshift Container Platform MEDIUM 5.5
CVE-2026-68742

A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining p…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-33591

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially …

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.3
CVE-2026-0392

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-69075

FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted …

Patch available
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-63563

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initi…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-62416

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accep…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-60011

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-8794

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnera…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-8793

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploi…

No fix yet
Fix from $1,600 2026-08-03