Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-75843

ArcadeDB before 26.8.1 fails to bind the authenticated principal on the gRPC transaction executor thread in beginTransaction, allowing authenticated …

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.7
CVE-2026-75842

ArcadeDB versions before 26.8.1 contain an arbitrary file read vulnerability in the OpenCypher LOAD CSV FROM clause that allows authenticated users t…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-75840

ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped re…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-75838

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detache…

No fix yet
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75837

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75836

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-75834

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). …

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.6
CVE-2026-75831

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the audio and video media rendering through the sourceParsedownElement met…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-75830

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batc…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-75829

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-75828

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75827

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-75107

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74906

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-74905

SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74904

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.6
CVE-2026-74902

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.7
CVE-2026-5224

Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-15585

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-75627

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers to bypass authentication fil…

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-75626

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject …

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-19608

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-19447

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2024-14046

A security vulnerability has been detected in OpenBoxes up to 0.9.1. This issue affects the function DocumentController of the file grails-app/contro…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-18929

Carbone is vulnerable to Denial of Service due to lack of protection against zip bombs when processing .docx files. The library uses yazl for zip dec…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-43971

Improper Encoding or Escaping of Output vulnerability in ninenines cowlib allows Link header directive smuggling via unescaped special characters in …

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2024-14045

A weakness has been identified in OpenBoxes up to 0.9.2. This vulnerability affects unknown code of the file grails-app/controllers/org/pih/warehouse…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-34884

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.1
CVE-2026-15371

Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked …

No fix yet
Fix from $4,900 2026-08-18