Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-54719

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?…

Patch available
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-54659

Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver…

Patch available
Fix from $1,600 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-54658

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl…

Patch available
Fix from $2,300 2026-07-28
Unclassified HIGH 8.6
CVE-2026-54650

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.P…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-54638

gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker con…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-47219

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9…

No fix yet
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 7.5
CVE-2026-55415

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.64.0+
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 7.5
CVE-2026-55391

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.63.0+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-55390

datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_gen…

Patch available
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 7.5
CVE-2026-55389

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.62.0+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.2
CVE-2026-54691

datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get…

Patch available
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 8.2
CVE-2026-54690

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.61.0+
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 7.8
CVE-2026-54656

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.60.2+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-54655

datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-54654

datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is r…

Patch available
Fix from $1,950 2026-07-28
Datamodel Code Generator HIGH 8.8
CVE-2026-54653

datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,…

Fix: 0.60.2+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-54621

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_cod…

Patch available
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive …

Mitigation only
Fix from $2,300 2026-07-28
Dompdf MEDIUM 5.3
CVE-2026-59943

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf …

Fix: 3.1.6+
Fix from $1,600 2026-07-28
Dompdf HIGH 7.5
CVE-2026-59942

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An at…

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Dompdf HIGH 7.5
CVE-2026-59941

Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared …

Fix: 3.1.6+
Fix from $1,950 2026-07-28
Dompdf MEDIUM 5.3
CVE-2026-56722

Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embed…

Fix: 3.1.6+
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-49447

Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18,…

Patch available
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-16581

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauth…

No fix yet
Fix from $1,600 2026-07-28
Websphere Application Server HIGH 8.1
CVE-2026-15328

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request …

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 8.7
CVE-2026-15325

IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of T…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-15280

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i…

Fix: 26.0.0.9+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 8.7
CVE-2026-15064

IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $1,950 2026-07-28
Websphere Application Server HIGH 7.5
CVE-2026-15057

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation.

Fix: 26.0.0.8+
Fix from $1,950 2026-07-28
Aspera Faspex HIGH 8.2
CVE-2026-14996

IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management.

Fix: 5.0.16+
Fix from $1,950 2026-07-28