Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Pgadmin 4 MEDIUM 5.4
CVE-2026-17350

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce its permission check consist…

Fix: 9.17+
Fix from $1,600 2026-07-31
Pgadmin 4 CRITICAL 9.6
CVE-2026-17349

/misc/workspace/adhoc_connect_server, part of the Workspaces feature introduced in pgAdmin 4 9.0, when passed the id of an existing server, clones th…

Fix: 9.17+
Fix from $2,300 2026-07-31
Pgadmin 4 MEDIUM 6.5
CVE-2026-17348

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's before_request hook only handles…

Fix: 9.17+
Fix from $1,600 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-17347

The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an administrator configure an external command that returns a per-user encryption…

Fix: 9.17+
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-16504

Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HT…

Mitigation only
Fix from $2,300 2026-07-31
Unclassified CRITICAL 9.1
CVE-2026-16503

Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default…

No fix yet
Fix from $2,300 2026-07-31
Pgadmin 4 HIGH 8.8
CVE-2026-17346

The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and switched sixteen COMMENT ON / pgstattuple / pgstatindex templates to it, but miss…

Fix: 9.17+
Fix from $1,950 2026-07-31
Zephyr HIGH 7.5
CVE-2026-10686

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing branches of ipv6_route_packet…

Fix: 4.5.0+
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-18446

fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash ba…

No fix yet
Fix from $1,950 2026-07-31
Zephyr HIGH 7.6
CVE-2026-10685

The Zephyr Bluetooth GATT client CCC-write response handler gatt_write_ccc_rsp() in subsys/bluetooth/host/gatt.c invoked the application's params->su…

Fix: 4.5.0+
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-28145

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects Ma…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-18358

A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the inco…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-17561

Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign…

No fix yet
Fix from $2,300 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-15227

Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" per…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.1
CVE-2026-46594

A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a speci…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.6
CVE-2026-46593

A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminP…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.9
CVE-2025-67651

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSit…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.6
CVE-2025-67650

An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an aut…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.3
CVE-2025-67649

A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into paramet…

No fix yet
Fix from $2,300 2026-07-31
Httpclient MEDIUM 5.3
CVE-2026-64607

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an inv…

Fix: 5.6.3+
Fix from $1,600 2026-07-31
Kyuubi HIGH 8.1
CVE-2026-62391

The security fix for CVE-2025-66518 is incomplete. Any client who can access to Apache Kyuubi Server via Kyuubi frontend protocols can bypass server-…

Fix: 1.12.0+
Fix from $1,950 2026-07-31
Zeppelin MEDIUM 6.5
CVE-2026-44615

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a not…

Fix: 0.12.1+
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-17567

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.2
CVE-2026-16843

Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid crede…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability c…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore RES…

No fix yet
Fix from $1,600 2026-07-31
Directory Server HIGH 7.5
CVE-2026-15722

A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit c…

No fix yet
Fix from $1,950 2026-07-31
Directory Server HIGH 7.5
CVE-2026-11770

A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-c…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 8.5
CVE-2026-10079

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identit…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 8.1
CVE-2026-65313

A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because…

No fix yet
Fix from $1,950 2026-07-31