Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Netty MEDIUM 5.5
CVE-2026-59919

Netty is an asynchronous, event-driven network application framework. In versions prior to 4.1.136.Final and 4.2.16.Final, Netty's HAProxy encoder ( …

Fix: 4.1.136 / 4.2.16+
Fix from $1,600 2026-07-29
Netty HIGH 7.5
CVE-2026-59901

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the `Bzip2Decoder` handler in…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-29
Netty MEDIUM 5.3
CVE-2026-59900

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, Netty's HTTP/2-to-HTTP/1.x tr…

Fix: 4.1.136 / 4.2.16+
Fix from $1,600 2026-07-29
Netty HIGH 7.5
CVE-2026-59899

Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, `HttpContentEncoder` (the sup…

Fix: 4.1.136 / 4.2.16+
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.3
CVE-2026-54705

MathLive provides web components for math display and input. Prior to 0.110.0, MathLive fails to escape text-mode content in \text{} and \mbox{} comm…

Patch available
Fix from $1,600 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-41939

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows u…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified HIGH 7.0
CVE-2026-40272

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) …

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-18236

A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or in…

Patch available
Fix from $2,300 2026-07-29
7 Zip HIGH 7.8
CVE-2026-14266

7-Zip XZ Decompression Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrar…

Fix: 26.02+
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-13723

A vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows an attacker to overwrite arbitrary files on macOS APFS by expl…

Patch available
Fix from $1,600 2026-07-29
Unclassified HIGH 8.7
CVE-2026-8339

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authentica…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.2
CVE-2026-8338

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malic…

No fix yet
Fix from $2,300 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-67194

Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow authenticated IMAP users to crash the imapd process via deeply nested parenthesi…

Patch available
Fix from $1,600 2026-07-29
Unclassified HIGH 7.8
CVE-2026-64560

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwo…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-64559

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer l…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-64558

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in pkey_pckmo handler implementation Explicitly check t…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.2
CVE-2026-54727

proot-distro is a utility for managing proot containers. Prior to version 5.1.6, proot-distro restore accepted hardlink entries whose linkname refere…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.2
CVE-2026-54693

ZITADEL is an open source identity management platform. From 2.43.0 through 2.71.19, from 3.0.0 until 3.4.11, and from 4.0.0 until 4.15.1, the email …

Patch available
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-54680

Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer Fluen…

Patch available
Fix from $2,300 2026-07-29
Unclassified HIGH 8.2
CVE-2026-54574

proot-distro is a utility for managing proot containers. Prior to version 5.1.5, proot-distro install extracted plain tarball root filesystems throug…

Patch available
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-51992

SQL Injection vulnerability in ClickHouse Server Versions <= 26.3.9.8 allows a remote attacker to execute arbitrary code via the create dictionaries …

Mitigation only
Fix from $2,300 2026-07-29
Undici MEDIUM 6.5
CVE-2026-16729

undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before 7.29.0, and from 8.0.0 up to …

Fix: 6.28.0 / 7.29.0+
Fix from $1,600 2026-07-29
Secure Firewall Management Center MEDIUM 5.3
CVE-2026-20316 KEV

A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log…

Fix: after 10.0.1
Fix from $1,600 2026-07-29
Unclassified MEDIUM 5.6
CVE-2026-18257

Improper validity period check for root issuer certificate in CycloneCrypto cryptographic wrapper of S2OPC allows a certificate issued by this root i…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.2
CVE-2026-18255

A flaw was found in Quay. A user configured in GLOBAL_READONLY_SUPER_USERS is able to view robot account tokens for repositories they are not a membe…

No fix yet
Fix from $1,950 2026-07-29
Fastify\/rate Limit MEDIUM 5.3
CVE-2026-15144

@fastify/rate-limit before 11.2.0 keys rate-limit buckets by the verbatim client IP string returned from request.ip. Because a single IPv6 client can…

Fix: 11.2.0+
Fix from $1,600 2026-07-29
Undici CRITICAL 9.1
CVE-2026-13697

undici's cache interceptor mishandles malformed Cache-Control private directives. In undici 7.0.0 up to before 7.29.0 and 8.0.0 up to before 8.9.0, a…

Fix: 7.29.0 / 8.9.0+
Fix from $2,300 2026-07-29
Unclassified HIGH 7.5
CVE-2025-60931

An Insecure Direct Object Reference (IDOR) in the Employee Compensation View function of Infor Global HR v11.24.10.01.33 allows unauthorized attacker…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-67193

Xlight FTP Server before 3.9.5 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the server's current …

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.1
CVE-2026-67192

Xlight FTP Server before 3.9.5 contains a pre-authentication stack buffer overflow vulnerability that allows unauthenticated attackers to corrupt sta…

No fix yet
Fix from $1,950 2026-07-29