Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-24185

NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, wh…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-24184

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an a…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-24183

NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-17106

The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.7
CVE-2025-9211

Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers …

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2025-9210

Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2021-43718

An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Se…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.0
CVE-2026-75625

Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache,…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.0
CVE-2026-75130

Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agent…

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-74044

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by s…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-74039

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to …

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.1
CVE-2026-74038

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrollin…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-73502

kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-derefer…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.6
CVE-2026-71880

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attacker…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-71879

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 all…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.2
CVE-2026-71878

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.8
CVE-2026-71551

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in …

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-69160

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use st…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-68923

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware on…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-68922

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py u…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-67921

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java comp…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-67920

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(),…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-67262

Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-66780

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce…

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63643

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js acc…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63642

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the …

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-61696

Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitt…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-54570

AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.9
CVE-2026-54552

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. …

Patch available
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-52610

An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on …

Fix unknown
Fix from $5,750 2026-08-18