Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.6
CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.2
CVE-2026-54605

OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parse…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 8.6
CVE-2026-54603

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relati…

Patch available
Fix from $1,950 2026-07-28
Gopacket HIGH 7.5
CVE-2026-54345

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtra…

Fix: 1.6.1+
Fix from $1,950 2026-07-28
Gopacket HIGH 7.5
CVE-2026-54332

gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads…

Fix: 1.6.1+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51275

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to ex…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51274

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers t…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 7.8
CVE-2026-51273

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded …

No fix yet
Fix from $1,950 2026-07-28
Unified Endpoint Manager MEDIUM 6.9
CVE-2026-18085

An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Po…

No fix yet
Fix from $1,600 2026-07-28
Unified Endpoint Manager MEDIUM 6.1
CVE-2026-18084

Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Sc…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.6
CVE-2026-16313

A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing contr…

Patch available
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-7868

IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrat…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.5
CVE-2026-7775

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 t…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.4
CVE-2026-67181

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.9
CVE-2026-66754

Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated at…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.4
CVE-2026-66752

tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a …

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.4
CVE-2026-66751

Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server …

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-66749

Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.8
CVE-2026-66748

Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage p…

Patch available
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.4
CVE-2026-66746

Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by em…

No fix yet
Fix from $1,600 2026-07-28
Edge MEDIUM 5.4
CVE-2026-62828

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-61609

Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProv…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 8.1
CVE-2026-54593

Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpo…

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 7.1
CVE-2026-54545

wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once …

Patch available
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51270

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function pars…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51268

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untr…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.6
CVE-2026-51271

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The fun…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.8
CVE-2026-51269

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51267

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application s…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51266

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynam…

No fix yet
Fix from $2,300 2026-07-28