Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.3
CVE-2026-67316

axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.9
CVE-2026-67315

axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing reques…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67314

axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpe…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67313

axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segm…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67312

axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON()…

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.8
CVE-2026-67311

Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects …

No fix yet
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-67310

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of …

No fix yet
Fix from $1,600 2026-08-01
Unclassified HIGH 7.8
CVE-2026-67309

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (…

Patch available
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.3
CVE-2026-67308

Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi…

No fix yet
Fix from $2,300 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67307

Wazuh 5.0.0-beta1 (fixed in 5.0.0-beta3) does not validate or override the cluster_name and cluster_node fields in inventory-sync Start FlatBuffer me…

Patch available
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.4
CVE-2026-67306

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_pla…

Patch available
Fix from $1,600 2026-08-01
Unclassified CRITICAL 9.4
CVE-2026-67305

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONT…

No fix yet
Fix from $2,300 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67304

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails.…

Patch available
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67301

FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing o…

Patch available
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67300

FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTI…

Patch available
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67299

FreeRDP before 3.29.0 contains a client-side heap use-after-free in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled …

Patch available
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67298

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels…

Patch available
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67297

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()…

No fix yet
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67296

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length b…

No fix yet
Fix from $1,950 2026-08-01
Unclassified MEDIUM 6.3
CVE-2026-67295

FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths …

Patch available
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.9
CVE-2026-67294

FreeRDP before 3.29.0 improperly validates the Extended Key Usage (EKU) purpose of the peer certificate during client-side server TLS authentication.…

Patch available
Fix from $1,600 2026-08-01
Unclassified MEDIUM 6.5
CVE-2026-67292

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The c…

Patch available
Fix from $1,600 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67291

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put()…

Patch available
Fix from $1,950 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67290

FreeRDP before 3.29.0 contains a heap out-of-bounds read vulnerability in the TSMF FFmpeg decoder when parsing AVC1 MPEG2VIDEOINFO media types with i…

Patch available
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-67289

FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetA…

Patch available
Fix from $2,300 2026-08-01
Unclassified HIGH 7.5
CVE-2026-67288

FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard cache request decoders that accept NULL NDR pointers for LookupN…

Patch available
Fix from $1,950 2026-08-01
Unclassified CRITICAL 9.8
CVE-2026-66402

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains multiple TLS certificate identity validation weaknesses in tls_verify_certificate(), tls…

Patch available
Fix from $2,300 2026-08-01
Zephyr MEDIUM 6.5
CVE-2026-2411

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose permission is hard-coded to …

Fix: 4.5.0+
Fix from $1,600 2026-08-01
Zephyr MEDIUM 5.4
CVE-2026-10773

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const char * name table after a faul…

Fix: 4.5.0+
Fix from $1,600 2026-08-01
Unclassified MEDIUM 5.1
CVE-2025-71404

better-auth versions after v0.0.2 and before 1.1.16 contain a reflected cross-site scripting (XSS) vulnerability on the /api/auth/error page, where t…

Patch available
Fix from $1,600 2026-08-01