Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.6
CVE-2026-71880

Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attacker…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-71879

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 all…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.2
CVE-2026-71878

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.8
CVE-2026-71551

Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in …

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-69160

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use st…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-68923

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware on…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.5
CVE-2026-68922

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py u…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.8
CVE-2026-67846

Berkeley Out-of-Order Machine (BOOM) commit 5223e44cfeb26f41380057a2eb4d651197475f69 contains a potential incorrect privilege assignment issue in the…

Fix unknown
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-67921

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java comp…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-67920

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the run.halo.app.migration.impl.MigrationServiceImpl.restoreWorkdir(),…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-67262

Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-66780

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce…

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63643

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js acc…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-63642

MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the …

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-61696

Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitt…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-54570

AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.9
CVE-2026-54552

sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. …

Patch available
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-52610

An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on …

Fix unknown
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecu…

Fix unknown
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-53533

aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-su…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.1
CVE-2026-52609

A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-52607

A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php files on the web server by s…

Fix unknown
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-50167

Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrievi…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-50161

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in …

Patch available
Fix from $5,750 2026-08-18
Unclassified HIGH 8.1
CVE-2026-50143

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-49452

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CS…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-48508

Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_p…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-44472

Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as suffic…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.3
CVE-2026-32657

Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, …

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2021-43717

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the…

Fix unknown
Fix from $5,750 2026-08-18