Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.1
CVE-2026-50735

pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, r…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.8
CVE-2026-49258

Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper…

Patch available
Fix from $1,950 2026-07-28
Bridge HIGH 8.6
CVE-2026-48396

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An a…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 8.6
CVE-2026-48395

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An att…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 7.8
CVE-2026-48394

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploita…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 7.8
CVE-2026-48393

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploita…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 7.8
CVE-2026-48392

Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploita…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 8.2
CVE-2026-48391

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 8.2
CVE-2026-48390

Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Bridge HIGH 7.8
CVE-2026-48374

Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary fi…

Fix: 15.1.7 / 16.0.6+
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.5
CVE-2026-47768

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key expos…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.1
CVE-2026-47726

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGe…

Patch available
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-47725

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DE…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.8
CVE-2026-18107

A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management …

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-16498

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode …

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.9
CVE-2026-16496

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow …

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing a…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-15304

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4.…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.6
CVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-59933

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.7
CVE-2026-59931

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through …

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-54635

pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDi…

Patch available
Fix from $1,950 2026-07-28
Photoshop Installer HIGH 8.6
CVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in t…

No fix yet
Fix from $1,950 2026-07-28
Format Plugins HIGH 7.8
CVE-2026-48372

Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current …

Fix: 2026.07+
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-48025

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 cons…

Patch available
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-67185

TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequenc…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-67184

TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sen…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-67183

TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.5
CVE-2026-67182

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare…

No fix yet
Fix from $1,950 2026-07-28