Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.7
CVE-2026-59644

In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender.

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59643

In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59642

In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle f…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59641

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59640

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle fo…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-59639

In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for …

Patch available
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-59638

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bounc…

Patch available
Fix from $2,300 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-15055

In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java…

Patch available
Fix from $1,600 2026-08-03
Unclassified HIGH 7.1
CVE-2026-12185

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Cast…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-3245

A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution.

No fix yet
Fix from $1,950 2026-08-03
N Central HIGH 8.1
CVE-2026-18577 KEV

An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1

Fix: 2026.3+
Fix from $1,950 2026-08-02
Zephyr HIGH 8.6
CVE-2026-10848

The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helpe…

Fix: 4.5.0+
Fix from $1,950 2026-08-02
Unclassified HIGH 7.1
CVE-2026-9856

A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue r…

Patch available
Fix from $1,950 2026-08-02
Zephyr MEDIUM 6.5
CVE-2026-10774

Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys…

Fix: 4.5.0+
Fix from $1,600 2026-08-02
Unclassified CRITICAL 9.8
CVE-2026-65321

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper …

Patch available
Fix from $2,300 2026-08-02
Unclassified MEDIUM 5.4
CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us…

No fix yet
Fix from $1,600 2026-08-02
Unclassified MEDIUM 6.5
CVE-2026-68582

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1…

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 8.1
CVE-2026-68581

Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independen…

Patch available
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-68580

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL …

No fix yet
Fix from $1,950 2026-08-02
Unclassified CRITICAL 9.6
CVE-2026-68579

FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows…

Patch available
Fix from $2,300 2026-08-02
Unclassified HIGH 7.5
CVE-2026-68578

ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently …

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 7.5
CVE-2026-67357

ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluste…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 8.8
CVE-2026-67356

ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe…

No fix yet
Fix from $1,950 2026-08-02
Unclassified MEDIUM 5.9
CVE-2025-71401

better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An …

No fix yet
Fix from $1,600 2026-08-02
Unclassified HIGH 7.1
CVE-2025-71400

better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth…

No fix yet
Fix from $1,950 2026-08-02
Unclassified HIGH 8.6
CVE-2025-71399

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments,…

Patch available
Fix from $1,950 2026-08-02
Unclassified MEDIUM 6.4
CVE-2026-12231

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v…

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs …

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak MEDIUM 6.5
CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing…

No fix yet
Fix from $1,600 2026-08-02
Build Of Keycloak HIGH 7.2
CVE-2026-18571

A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi…

No fix yet
Fix from $1,950 2026-08-02