Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-53503

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.7
CVE-2026-53502

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boun…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.2
CVE-2026-53501

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s …

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.2
CVE-2026-53500

Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() …

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 7.3
CVE-2026-18481

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal sessi…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.7
CVE-2026-55100

hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier value…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 7.3
CVE-2026-54737

@phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursi…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.7
CVE-2026-54729

DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost …

Patch available
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.6
CVE-2026-54725

vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in …

Patch available
Fix from $2,300 2026-07-31
Fms Employee MEDIUM 5.4
CVE-2026-34497

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site…

Fix: after 2025.3.1
Fix from $1,600 2026-07-31
Fms Employee MEDIUM 5.4
CVE-2026-34495

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Sto…

Fix: after 2025.3.1
Fix from $1,600 2026-07-31
Xaap MEDIUM 5.5
CVE-2026-34490

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherw…

Fix: 1.53+
Fix from $1,600 2026-07-31
Fms Employee CRITICAL 9.8
CVE-2026-21662

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec…

Fix: after 2025.3.1
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-67822

Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sp…

No fix yet
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.4
CVE-2026-58048

Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context.

No fix yet
Fix from $2,300 2026-07-31
Unclassified MEDIUM 5.6
CVE-2026-58047

HTTP Smuggling in cPanel allows potential leak of credentials.

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.4
CVE-2026-54707

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Pri…

Patch available
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-52856

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received dur…

Patch available
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.9
CVE-2026-52855

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg…

Patch available
Fix from $2,300 2026-07-31
Unclassified MEDIUM 5.9
CVE-2026-67607

LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftp…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-59232

Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead per…

Patch available
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-59231

Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requ…

Patch available
Fix from $1,600 2026-07-31
Icontrol MEDIUM 5.3
CVE-2026-56568

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra…

No fix yet
Fix from $1,600 2026-07-31
Icontrol MEDIUM 5.3
CVE-2026-56571

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa…

No fix yet
Fix from $1,600 2026-07-31
Icontrol MEDIUM 5.3
CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.1
CVE-2026-56567

HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.5
CVE-2026-52857

Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml c…

Patch available
Fix from $1,600 2026-07-31
Unclassified HIGH 8.2
CVE-2026-18141

A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypa…

No fix yet
Fix from $1,950 2026-07-31
Pgadmin 4 CRITICAL 9.9
CVE-2026-17566

pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passi…

Fix: 9.18+
Fix from $2,300 2026-07-31
Pgadmin 4 CRITICAL 9.0
CVE-2026-17351

The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlpar…

Fix: 9.17+
Fix from $2,300 2026-07-31