Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Ffmpeg HIGH 7.8
CVE-2026-66041

FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out-of-bounds write vulnerability in the vf_quirc filter that allows an attacker t…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Ffmpeg HIGH 8.8
CVE-2026-66040

FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of-bounds write vulnerability in the native PNG and APNG encoders that allows remo…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Ffmpeg HIGH 7.8
CVE-2026-66039

FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integer overflow vulnerability in the MACE6 audio decoder that allows attackers to c…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Ffmpeg MEDIUM 6.5
CVE-2026-66038

FFmpeg through 8.1.2, fixed in commit 8670835, contains an information disclosure vulnerability in the LCL/ZLIB video decoder that allows attackers t…

Fix: after 8.1.2
Fix from $1,600 2026-07-24
Ffmpeg MEDIUM 5.5
CVE-2026-66037

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolled resource consumption vulnerability in the IAMF demuxer that allows an unauthe…

Fix: after 8.1.2
Fix from $1,600 2026-07-24
Ffmpeg HIGH 8.8
CVE-2026-66036

FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of-bounds write vulnerability in the vf_hqdn3d filter that allows attackers to cor…

Fix: after 8.1.2
Fix from $1,950 2026-07-24
Azure Portal HIGH 7.5
CVE-2026-62835

Improper authorization in Azure Portal allows an unauthorized attacker to disclose information over a network.

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-57531

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allows unauthenticated attackers …

Patch available
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-57530

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milkdown/components packages that…

Patch available
Fix from $1,600 2026-07-24
Unclassified HIGH 8.1
CVE-2026-54342

In epa4all, prior to version 2026-05-20, an attacker on the network path between epa4all and any backend (ePA Aktensystem, Konnektor, IDP, TSS) can p…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.3
CVE-2026-48037

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, Accoun…

Patch available
Fix from $1,600 2026-07-24
Unclassified HIGH 8.4
CVE-2026-48036

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consum…

Patch available
Fix from $1,950 2026-07-24
Unclassified HIGH 7.1
CVE-2026-48035

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consum…

Patch available
Fix from $1,950 2026-07-24
Unclassified HIGH 8.5
CVE-2026-48034

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there …

Patch available
Fix from $1,950 2026-07-24
Unclassified HIGH 8.4
CVE-2026-48033

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, policy…

Patch available
Fix from $1,950 2026-07-24
Unclassified HIGH 8.3
CVE-2026-48032

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-ro…

Patch available
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.1
CVE-2026-48021

In epa4all, prior to version 2026-05-20, an attacker who can intercept the TLS connection between epa4all and the ePA backend can complete the VAU ha…

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 8.5
CVE-2026-17107

A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-eng…

No fix yet
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66035

libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authentication heap buffer overflow vulnerability that allows a malicious SSH server …

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66034

libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bounds check vulnerability that allows a malicious SSH server to trigger an arbit…

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 7.5
CVE-2026-66033

libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authentication integer underflow vulnerability in the ssh2_cipher_crypt() function in…

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Libssh2 HIGH 8.8
CVE-2026-66032

libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicio…

Fix: after 1.11.1
Fix from $1,950 2026-07-24
Unclassified HIGH 7.2
CVE-2026-65711

sysPass through version 3.2.11 contains an OS command injection vulnerability that allows authenticated administrators to execute arbitrary commands …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.1
CVE-2026-65710

sysPass through version 3.2.11 contains a missing authorization vulnerability that allows authenticated users with the PUBLICLINK_CREATE profile flag…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.3
CVE-2026-65709

sysPass through version 3.2.11 contains a missing object-level authorization vulnerability in the JSON-RPC API that allows API token holders to enume…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.1
CVE-2026-65708

sysPass through version 3.2.11 contains an insecure direct object reference vulnerability that allows any authenticated attacker to access account fi…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-65707

Likeshop through 3.0.5 contains an authenticated SQL injection vulnerability that allows admin-level users to extract arbitrary database contents by …

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.7
CVE-2026-65623

Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion during WebSocke…

Patch available
Fix from $1,950 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64254

In the Linux kernel, the following vulnerability has been resolved: NTB: epf: Avoid pci_iounmap() with offset when PEER_SPAD and CONFIG share BAR W…

Fix: 6.1.177 / 6.6.144+
Fix from $1,600 2026-07-24
Linux Kernel MEDIUM 5.5
CVE-2026-64253

In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk…

Fix: 6.12.95 / 6.18.38+
Fix from $1,600 2026-07-24