Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Openvpn HIGH 8.1
CVE-2026-13117

An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Openvpn HIGH 8.1
CVE-2026-12996

A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Langflow HIGH 7.1
CVE-2026-12945

IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on …

Fix: 1.10.2+
Fix from $1,950 2026-07-30
Langflow CRITICAL 9.8
CVE-2026-12940

IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C…

Fix: 1.10.2+
Fix from $2,300 2026-07-30
Openvpn HIGH 8.1
CVE-2026-12932

A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Unclassified HIGH 8.4
CVE-2026-11885

IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call…

No fix yet
Fix from $1,950 2026-07-30
Openvpn HIGH 7.5
CVE-2026-11771

OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to…

Fix: 2.6.21 / 2.7.5+
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.2
CVE-2026-67596

CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all st…

No fix yet
Fix from $1,600 2026-07-30
Kyuubi CRITICAL 9.8
CVE-2026-52680

Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote …

Fix: 1.12.0+
Fix from $2,300 2026-07-30
Unclassified HIGH 8.8
CVE-2026-58222

A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When…

Mitigation only
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-58216

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.5
CVE-2026-57862

Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin…

No fix yet
Fix from $1,950 2026-07-30
Zeppelin MEDIUM 6.5
CVE-2026-44617

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters ins…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Zeppelin MEDIUM 6.5
CVE-2026-44616

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, al…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Zeppelin MEDIUM 6.1
CVE-2026-44613

Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a…

Fix: 0.12.1+
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-4978

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL …

No fix yet
Fix from $2,300 2026-07-30
Jspwiki MEDIUM 6.5
CVE-2026-48910

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could …

Fix: 2.12.4+
Fix from $1,600 2026-07-30
Jspwiki HIGH 7.5
CVE-2026-28814

Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Jspwiki HIGH 8.8
CVE-2026-28813

Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Jspwiki CRITICAL 9.8
CVE-2026-28812

UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende…

Fix: 2.12.4+
Fix from $2,300 2026-07-30
Jspwiki HIGH 7.5
CVE-2026-28811

Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this…

Fix: 2.12.4+
Fix from $1,950 2026-07-30
Web Help Desk CRITICAL 9.8
CVE-2026-28323

SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b…

Fix: 2026.2.1+
Fix from $2,300 2026-07-30
Superset MEDIUM 6.5
CVE-2026-23985

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in …

Fix: 6.0.0+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-23981

An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboar…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.1
CVE-2026-15658

A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of o…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-15657

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the respons…

No fix yet
Fix from $1,600 2026-07-30
Websphere Application Server HIGH 7.5
CVE-2026-10842

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-30
Calico HIGH 7.5
CVE-2026-6540

Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re…

Fix: 3.21.7 / 3.22.4+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-67349

OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud…

Patch available
Fix from $1,950 2026-07-30
Unclassified HIGH 8.1
CVE-2026-67348

Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anot…

No fix yet
Fix from $1,950 2026-07-30