Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-52735

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, Zebra can accept a block that zcashd rejects because the P2SH signature-operation cou…

Patch available
Fix from $5,750 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-52734

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated P2P peer can cause the mempool download pipeline to retain transac…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-52481

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the tcp_actions() function

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-52480

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via the inetd service

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-52733

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave stale Sapling and Orchard note-…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-52732

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, one unauthenticated P2P peer can monopolize all 25 MAX_INBOUND_CONCURRENCY slots in Z…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-52731

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoint can terminate zebrad by su…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.0
CVE-2026-49500

Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerab…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-47721

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-47720

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString functio…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 8.2
CVE-2026-47719

FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO han…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-19671

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extractin…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-19670

Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /au…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.4
CVE-2026-12520

The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) …

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-70667

Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-65959

Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoin…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-55166

Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si…

Patch available
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-55163

Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(ro…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-55162

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from upl…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-47630

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit migh…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-47629

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-47628

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successf…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-47627

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to de…

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-47606

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit migh…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.1
CVE-2026-24185

NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, wh…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-24184

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an a…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-24183

NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-17106

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.7
CVE-2025-9211

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers …

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2025-9210

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es…

No fix yet
Fix from $4,900 2026-08-18