Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.1
CVE-2026-30250

Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to …

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.6
CVE-2026-19869

@neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-le…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.6
CVE-2026-75926

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could no…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75915

CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process e…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75914

CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading …

Patch available
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-75913

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-sup…

Patch available
Fix from $5,750 2026-08-18
Unclassified HIGH 7.4
CVE-2026-75912

CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by i…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-75911

CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to e…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75859

CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on …

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-75858

CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. Th…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.0
CVE-2026-75857

CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement r…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.6
CVE-2026-75856

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-75485

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, …

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-73834

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed …

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.9
CVE-2026-73373

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not incl…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-73371

Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthori…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.2
CVE-2026-73337

Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-73073

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-72532

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.5
CVE-2026-71574

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.7
CVE-2026-71477

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.7
CVE-2026-71365

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.8
CVE-2026-63328

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins wit…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-62357

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whos…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-55839

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-49227

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment opera…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-49226

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operatio…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-49221

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-46482

### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challe…

Patch available
Fix from $4,000 2026-08-18