Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Ipados MEDIUM 6.5
CVE-2026-65330

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. An app may be able to…

Fix: 26.6.1 / 26.6.2+
Fix from $4,000 2026-08-17
Ipados MEDIUM 5.9
CVE-2026-65329

An authentication issue was addressed with improved state management. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1. An attacker in a privilege…

Fix: 26.6.1+
Fix from $4,000 2026-08-17
Ipados MEDIUM 5.4
CVE-2026-64788

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. Processing maliciousl…

Fix: 26.6.1 / 26.6.2+
Fix from $4,000 2026-08-17
Safari MEDIUM 6.5
CVE-2026-64787

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe…

Fix: 26.6.1 / 26.6.2+
Fix from $4,000 2026-08-17
Mlflow CRITICAL 9.3
CVE-2026-64849 KEVEPSS 8%

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated…

Fix: 3.15.0+
Fix from $5,750 2026-08-17
Safari MEDIUM 6.5
CVE-2026-64778

The issue was addressed with improved checks. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.1 and iPadOS 26.6.1, mac…

Fix: 18.7.10 / 26.6.1+
Fix from $4,000 2026-08-17
Ipados MEDIUM 5.5
CVE-2026-64760

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An app may be able to leak se…

Fix: 18.7.10+
Fix from $4,000 2026-08-17
Safari MEDIUM 6.5
CVE-2026-64715

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6.…

Fix: 18.7.10 / 26.6.1+
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-63178

Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Edition's PATCH /manage/admin/user-group/{user_group_id} and POST /manage/admin/u…

Patch available
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-51977

An issue in Trueview T18061 WiFi 3MP Robot Pan-Tilt Security Camera Version 1.0 allows a physically proximate attacker to escalate privileges via the…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 8.6
CVE-2026-56677

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/oidc/test/route.js passes the …

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.9
CVE-2026-45791

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's user.update procedure in apps/dokploy/server/api/routers/us…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 8.0
CVE-2026-45790

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy's organization.inviteMember tRPC procedure in apps/dokploy/se…

Patch available
Fix from $4,900 2026-08-17
Safari HIGH 8.8
CVE-2026-43794

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6…

Fix: 18.7.10 / 26.6.1+
Fix from $4,900 2026-08-17
Ipados MEDIUM 6.5
CVE-2026-43667

A reachable assertion was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10. An attacker in a privilege…

Fix: 18.7.10+
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-42163

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoperability (LTI) under certain c…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-11817

This vulnerability only affects Grafana stacks configured with multiple organizations; single-organization deployments are not impacted. In a multi-o…

No fix yet
Fix from $4,000 2026-08-17
Mattermost Server MEDIUM 6.5
CVE-2026-10080

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fails to validate WebSocket command field types which allows an authentic…

Fix: 10.11.22 / 11.7.7+
Fix from $4,000 2026-08-17
Unclassified HIGH 7.0
CVE-2026-75531

Pandora contains a stored cross-site scripting (XSS) vulnerability in the rendering of URL observables. A URL extracted from or associated with an an…

Patch available
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.9
CVE-2026-75529

Pandora is affected by a stored cross-site scripting vulnerability in the PDF download functionality. The /task-download/<task_id>/.../pdf endpoint v…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75482

SWE-agent's trajectory inspector (sweagent inspector), confirmed in v1.1.0, is an HTTP server that joins request paths to the trajectory directory in…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-75481

SkyPilot fails to validate that authenticated users are entitled to grant administrator roles when updating service account permissions. Attackers ca…

Patch available
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75480

OpenViking debug vector scroll and count endpoints apply only account-level scoping without user-level access controls, allowing authenticated users …

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75479

JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to en…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75111

Evidently UI fails to properly validate the filename parameter in the dataset materialization endpoint, allowing unauthenticated attackers to read ar…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-75110

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=true) but the undocumented, d…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 7.1
CVE-2026-75109

Determined fails to authorize requests on the generic task kill, pause, and unpause endpoints in the API handlers. Authenticated attackers can disrup…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-75108

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any authenticated user to probe …

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-75106

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attack…

Patch available
Fix from $5,750 2026-08-17
Unclassified HIGH 7.5
CVE-2026-75105

phpIPAM through 1.8.1 fails to verify that a requested IP address belongs to the subnet a temporary share token was issued for. In app/temp_share/ind…

Patch available
Fix from $4,900 2026-08-17