Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.3
CVE-2026-16796

Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remot…

No fix yet
Fix from $1,950 2026-07-23
Unclassified HIGH 8.2
CVE-2026-16002

The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service.

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15981

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is …

No fix yet
Fix from $2,300 2026-07-23
Moveit Transfer MEDIUM 5.4
CVE-2026-15968

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects M…

Fix: 2025.1.5 / 2026.0.3+
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…

No fix yet
Fix from $2,300 2026-07-23
Moveit Transfer CRITICAL 9.8
CVE-2026-15967

Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before…

Fix: 2025.1.5 / 2026.0.3+
Fix from $2,300 2026-07-23
Moveit Transfer CRITICAL 9.8
CVE-2026-15966

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before…

Fix: 2025.1.5 / 2026.0.3+
Fix from $2,300 2026-07-23
Moveit Transfer CRITICAL 9.8
CVE-2026-10697

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.…

Fix: 2025.1.5 / 2026.0.3+
Fix from $2,300 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65706

FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap …

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65705

FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap…

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-64785

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend thro…

No fix yet
Fix from $1,600 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65704

FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat fil…

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Ffmpeg HIGH 7.8
CVE-2026-65703

FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap c…

Fix: after 8.1.2
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-63359

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-cra…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified HIGH 7.8
CVE-2026-60122

gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who cont…

Patch available
Fix from $1,950 2026-07-23
Unclassified HIGH 8.7
CVE-2026-47722

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86…

Patch available
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.4
CVE-2026-47670

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-47669

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.5
CVE-2026-25800

Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, th…

Patch available
Fix from $1,950 2026-07-23
Unclassified HIGH 8.8
CVE-2026-15212

The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_S…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-12353

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TL…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.6
CVE-2026-65010

Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to writ…

Patch available
Fix from $1,600 2026-07-23
Unclassified HIGH 8.2
CVE-2026-63765

Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to crea…

Patch available
Fix from $1,950 2026-07-23
Unclassified HIGH 7.5
CVE-2026-16756

Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-serv…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 7.5
CVE-2026-65919

Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoint…

Patch available
Fix from $1,950 2026-07-23
Torchvision HIGH 7.1
CVE-2026-65918

PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor …

Fix: after 0.28.0
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.1
CVE-2026-65763

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vul…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.1
CVE-2026-65762

Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XS…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.6
CVE-2026-65702

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated re…

No fix yet
Fix from $1,950 2026-07-23