Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.9
CVE-2026-67355

guzzlehttp/guzzle versions before 7.15.1 fail to preserve host-only cookie scope, storing the request host in the Domain field instead of marking coo…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.9
CVE-2026-67354

guzzlehttp/guzzle versions before 7.15.1 contain an information disclosure vulnerability in RedirectMiddleware. When the optional allow_redirects.ref…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67353

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimited Set-Cookie header fields w…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.6
CVE-2026-67352

luci-app-https-dns-proxy contains a stored cross-site scripting vulnerability in the resolver_url parameter that allows authenticated users to inject…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.8
CVE-2026-67343

ArcadeDB versions before 26.7.2 fail to properly redact the cluster token in the GET /api/v1/server endpoint, allowing authenticated users to retriev…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67342

ArcadeDB versions before 26.7.2 contain an authorization bypass vulnerability in HTTP handlers for time series, batch, Prometheus, and Grafana endpoi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67341

ArcadeDB versions before 26.7.2 fail to enforce scripting authorization checks on the SQL DEFINE FUNCTION statement with LANGUAGE js. Attackers with …

No fix yet
Fix from $2,300 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67340

ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) because ScriptTriggerExecutor …

Mitigation only
Fix from $2,300 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cURL handlers. Attackers can cap…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.1
CVE-2026-67338

JupyterLab before 4.5.9 contains a stored cross-site scripting vulnerability in the Extension Manager that fails to validate URI protocols in package…

Patch available
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-67337

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is enabled. Attackers with valid …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.7
CVE-2026-67336

better-auth versions before 1.6.11 contain insecure cryptographic defaults in the oidcProvider and mcp plugins that advertise the none algorithm and …

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 5.3
CVE-2026-67335

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-backed state storage without …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.2
CVE-2026-67333

better-auth before 1.6.13 (and pre-release builds 1.7.0-beta.0 through 1.7.0-beta.3) fail to validate the scheme of redirect_uris registered via the …

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.4
CVE-2026-67332

@better-auth/oauth-provider before 1.7.0-beta.4 fails to bind access-token audience to the authorization grant, allowing clients to request tokens fo…

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67331

better-auth SCIM versions from 1.5.0 before 1.7.0-beta.4 fail to bind non-organization SCIM providers to their creator by default, allowing authentic…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.9
CVE-2026-67330

@better-auth/scim (a better-auth plugin) versions >= 1.4.0-beta.27 through <= 1.6.21 and >= 1.7.0-beta.0 through <= 1.7.0-beta.9 contain an authoriza…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 7.1
CVE-2026-67329

@better-auth/stripe versions >= 1.4.11 and < 1.6.21, and >= 1.7.0-beta.0 and < 1.7.0-beta.10, contain an authorization bypass in organization subscri…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.1
CVE-2026-67328

@better-auth/sso versions before 1.6.21 contain multiple authentication bypass vulnerabilities in SSO provider handling that allow attackers to sign …

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67327

better-auth versions >= 1.1.3 and < 1.6.22 (and pre-release versions >= 1.7.0-beta.0 and < 1.7.0-beta.10) are vulnerable to account takeover via pre-…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.0
CVE-2026-67326

GitPython before 3.1.50 fails to validate newline characters in the section parameter of config_writer(), allowing attackers to inject arbitrary sect…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 8.8
CVE-2026-67325

GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. A…

No fix yet
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67324

GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default …

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 8.4
CVE-2026-67323

GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing comm…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67322

GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.9
CVE-2026-67321

axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 8.3
CVE-2026-67320

axios in a Node.js deployment using the HTTP adapter can route requests through an attacker-controlled proxy. axios hardens merged request configurat…

Patch available
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67319

axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67318

axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent w…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67317

axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length ca…

No fix yet
Fix from $1,600 2026-08-01