Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-5491

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.8
CVE-2026-5490

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-5489

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-5487

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-5057

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-serv…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-5056

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.4
CVE-2026-18266

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affe…

No fix yet
Fix from $1,600 2026-07-29
Pgvector HIGH 8.8
CVE-2026-18022

Integer wraparound in IVFFlat index build in pgvector before 0.8.6 allows a database user to write data out-of-bounds, which could lead to arbitrary …

Fix: 0.8.6+
Fix from $1,950 2026-07-29
GitLab MEDIUM 5.4
CVE-2026-16553

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under cer…

Fix: 19.0.5 / 19.1.3+
Fix from $1,600 2026-07-29
GitLab HIGH 7.5
CVE-2026-15975

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …

Fix: 19.0.5 / 19.1.3+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-13268

G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate p…

No fix yet
Fix from $1,950 2026-07-29
GitLab MEDIUM 5.3
CVE-2026-13113

GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under cer…

Fix: 19.0.5 / 19.1.3+
Fix from $1,600 2026-07-29
GitLab HIGH 8.4
CVE-2026-12436

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under …

Fix: 19.0.5 / 19.1.3+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.2
CVE-2026-12357

Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 10.0
CVE-2026-67429

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, image.download and related file-writing modules use caller…

Patch available
Fix from $2,300 2026-07-29
Unclassified HIGH 8.5
CVE-2026-67428

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, HTTP-emitting modules including src/core/modules/third_par…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.6
CVE-2026-67427

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable resolver expands ${env.VAR} f…

Patch available
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-67426

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the standalone flyto-verification service in src/core/veri…

Patch available
Fix from $2,300 2026-07-29
Unclassified HIGH 8.6
CVE-2026-67425

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys such as OPENAI_API_KEY and AN…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.5
CVE-2026-67424

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.7, the HTTP modules http.get, http.request, and http.batch in…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.6
CVE-2026-67201

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows attackers to circumvent host…

Patch available
Fix from $1,950 2026-07-29
Netty HIGH 7.5
CVE-2026-59898

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, ab attacker can force WebSoc…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-29
Websphere Application Server HIGH 8.8
CVE-2026-2482

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is vulnerable to cross-site request forgery which could allow an attacker to exe…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-29
Unclassified HIGH 8.6
CVE-2026-16328

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to overrid…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 10.0
CVE-2026-16326

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authen…

No fix yet
Fix from $2,300 2026-07-29
Websphere Application Server CRITICAL 9.8
CVE-2026-14529

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 traditional is vulnerable to s…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-29
Pip MEDIUM 6.5
CVE-2026-13346

pip would incorrectly handle doubly-encoded package URLs from indexes allowing for files to be installed to arbitrary locations on disk even when ins…

Fix: 26.2+
Fix from $1,600 2026-07-29
Unclassified HIGH 8.7
CVE-2026-12935

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occ…

No fix yet
Fix from $1,950 2026-07-29
Password Manager HIGH 7.4
CVE-2026-8497

Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS,…

Fix: 2026.2.2.0+
Fix from $1,950 2026-07-29
Netty MEDIUM 6.5
CVE-2026-59920

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's STOMP encoder ( St…

Fix: 4.1.136 / 4.2.16+
Fix from $1,600 2026-07-29