Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-67191

Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write…

No fix yet
Fix from $2,300 2026-07-29
Ait Dsn CRITICAL 9.8
CVE-2026-60113

AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte…

Fix: 2.2.2+
Fix from $2,300 2026-07-29
Ait Gui CRITICAL 9.8
CVE-2026-60112

AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o…

Fix: 2.5.1+
Fix from $2,300 2026-07-29
Prebid Server CRITICAL 10.0
CVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in …

Fix: 4.4.0+
Fix from $2,300 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-54082

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an …

Patch available
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.9
CVE-2026-54081

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-par…

Patch available
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.9
CVE-2026-54080

veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-par…

Patch available
Fix from $1,600 2026-07-29
Unclassified HIGH 8.7
CVE-2026-54079

veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-valid…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-54078

veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an …

Patch available
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.9
CVE-2026-50558

Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in p…

Patch available
Fix from $1,600 2026-07-29
Advance Steel MEDIUM 5.5
CVE-2026-17550

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can lev…

Fix: 2026.1.2+
Fix from $1,600 2026-07-29
Unclassified HIGH 7.1
CVE-2026-16543

Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w…

No fix yet
Fix from $1,950 2026-07-29
Advance Steel HIGH 7.1
CVE-2026-16465

A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can lev…

Fix: 2026.1.2+
Fix from $1,950 2026-07-29
Advance Steel HIGH 7.8
CVE-2026-16463

A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t…

Fix: 2026.1.2+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.1
CVE-2026-15228

Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-66724

MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoi…

No fix yet
Fix from $1,600 2026-07-29
Gridbox HIGH 7.3
CVE-2026-65947

Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.0
CVE-2026-66723

MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify…

No fix yet
Fix from $1,950 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65888

Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65887

Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox HIGH 7.5
CVE-2026-65886

Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view …

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Unclassified HIGH 7.6
CVE-2026-59247

Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents dur…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54666

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts p…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54664

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parser…

Patch available
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.1
CVE-2026-54663

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpR…

Patch available
Fix from $1,600 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54662

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfi…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.3
CVE-2026-54661

swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-ht…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 7.4
CVE-2026-54660

swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo…

Patch available
Fix from $1,950 2026-07-29
Unclassified HIGH 8.0
CVE-2026-12703

TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a co…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.4
CVE-2026-9177

A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in vers…

No fix yet
Fix from $2,300 2026-07-29