Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-51263

schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON r…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.2
CVE-2026-47483

NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource co…

No fix yet
Fix from $1,950 2026-07-28
Mcp Server HIGH 7.5
CVE-2026-47427

GitHub MCP Server is GitHub's official MCP Server. Prior to 1.1.0, the CompletionsHandler function in pkg/github/server.go accesses params.Ref withou…

Fix: 1.1.0+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.6
CVE-2026-45293

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.14.1 until 3.4.1, the WordPre…

Patch available
Fix from $1,950 2026-07-28
Java Client HIGH 8.2
CVE-2026-43910

Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when di…

Fix: 10.1.1+
Fix from $1,950 2026-07-28
Unclassified HIGH 7.3
CVE-2026-8164

Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Orde…

No fix yet
Fix from $1,950 2026-07-28
Mattermost Server MEDIUM 5.5
CVE-2026-7521

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to verify file deletion path which allows an admin…

Fix: 10.11.21 / 11.6.6+
Fix from $1,600 2026-07-28
Unclassified HIGH 7.8
CVE-2026-67178

MISP installation scripts generated an Apache HTTP virtual-host configuration containing an incorrectly formatted HTTP-to-HTTPS redirect: Redirect p…

Patch available
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.2
CVE-2026-67174

Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHT…

Patch available
Fix from $2,300 2026-07-28
Axis2\/java CRITICAL 9.8
CVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0…

Fix: 2.0.1+
Fix from $2,300 2026-07-28
Tomcat HIGH 7.5
CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through…

Fix: 9.0.121 / 10.1.58+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-63727

Anchore Enterprise versions from 5.11.0 to 5.27.1 and 6.0.0 contain an improper privilege escalation vulnerability in the user management API. An aut…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51261

Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5 creates a race condition between concurrent tasks. The…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-51260

Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code cop…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51259

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subs…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 7.8
CVE-2026-51254

schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerability in the MP3Decoder::GetBits() function of the MP3 decoder due to unchecked b…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51252

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on at…

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 7.5
CVE-2026-51251

Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::decode() function of the MP3 decoder due to missing size val…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.1
CVE-2026-67173

Pivotick did not validate the URL scheme of node imagePath values derived from graph data before assigning them to SVG image resources. An attacker a…

Patch available
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.1
CVE-2026-66922

Pivotick used plain JavaScript objects as lookup tables indexed by caller-controlled graph node identifiers in its tree-layout and cycle-detection co…

Patch available
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.3
CVE-2026-66921

Pivotick’s Markdown node-reference renderer failed to HTML-escape the attacker-controlled nodeName value before interpolating it into both the data-n…

Patch available
Fix from $1,600 2026-07-28
Activemq MEDIUM 6.5
CVE-2026-61487

Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. An authenticated low-privilege user can bypas…

Fix: 5.19.9 / 6.2.8+
Fix from $1,600 2026-07-28
Activemq HIGH 7.5
CVE-2026-59878

Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apache ActiveMQ, Apache ActiveMQ All. A remote unauthenticated peer that can reach …

Fix: 5.19.9 / 6.2.8+
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-7187

Missing authentication for critical function vulnerability in Universal Software Inc. UKBS allows Accessing Functionality Not Properly Constrained by…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.2
CVE-2026-66920

Pivotick contains an uncontrolled-recursion vulnerability when processing caller-supplied graph and node data. The affected graph algorithms recursiv…

Patch available
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-66919

Pivotick contains a cross-site scripting vulnerability in the inspect and edit node modals. Node labels and descriptions originating from graph data …

Patch available
Fix from $1,600 2026-07-28
Unclassified HIGH 8.2
CVE-2026-66918

Pivotick fails to sanitize attacker-controlled SVG markup supplied through the per-node style.svgIcon property before inserting it into the document.…

Patch available
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-66913

Lookyloo did not enforce limits on the decompressed size of uploaded capture archives and compressed HAR files. An attacker could submit a specially…

Patch available
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.1
CVE-2026-65882

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a ref…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-65881

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration …

No fix yet
Fix from $1,950 2026-07-28