Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecu…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-53533

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-su…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.1
CVE-2026-52609

A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-52607

A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by s…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-50167

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrievi…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-50161

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in …

Patch available
Fix from $5,750 2026-08-18
Unclassified HIGH 8.1
CVE-2026-50143

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-49452

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CS…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-48508

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_p…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-44472

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as suffic…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.3
CVE-2026-32657

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-75924

A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secr…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75897

Improper input validation in the capabilities route handler in OpenSearch Dashboards - the size of the request payload is not bounded - might allow r…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-73372

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access che…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-73336

Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in sche…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-72531

Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check …

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-71573

Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2026-70415

Dell PowerStore SDNAS contains a Buffer Copy without Checking Size of Input vulnerability in the NFS/RPC. An unauthenticated attacker with remote acc…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-69220

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/jav…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-69219

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/jav…

Patch available
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-67271

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentiall…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.2
CVE-2026-66783

A flaw was found in the `submariner-operator` component of Red Hat Advanced Cluster Management for Kubernetes. This vulnerability allows a cluster ad…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-66782

A flaw was found in the Submariner operator. This vulnerability allows for the exposure of a long-lived broker service account (SA) bearer token with…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-66781

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectivity, stores the IPsec pre-sha…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-63337

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-63336

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63335

The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-61574

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the Remote Access Control endpoint list returns every configured endpo…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.4
CVE-2026-57580

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK o…

Patch available
Fix from $5,750 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-55106

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, a diagnostic action on the LDAP Source API does not enforce the object…

Patch available
Fix from $4,000 2026-08-18