Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.5
CVE-2026-75104

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitrary files outside the model d…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 8.8
CVE-2026-75103

Crawlab fails to verify user ownership or administrative role on the password-change endpoint, allowing any authenticated user to reset any account's…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-73560

vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the MiMoV2OmniMultiModalProcessor in vllm/transformers_utils/proc…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 8.5
CVE-2026-73410

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a validated address through a …

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-71518

Typemill before 2.26.0 contains an authorization bypass vulnerability in the media file download route that allows unauthenticated attackers to acces…

Patch available
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-68765

hashcat master branch builds after v7.1.2 contain a heap buffer overflow vulnerability in the KeePass AESKDF/KDBX v4 module (module 34301) that allow…

Patch available
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67967

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an incomplete fix for CVE-2025-448…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67966

Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemon and obtain root shell acces…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67965

An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login function

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67926

An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-67925

Cross Site Scripting vulnerability in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the endpoint /airag/chat/upload

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67917

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality. The `azuracast:restore` comma…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-66795

A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSR…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-65976

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.300, a connected peer can send repeated DCLP DataChunk messag…

Patch available
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-65974

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, limited authenticated users can cross a permissio…

Patch available
Fix from $5,750 2026-08-17
Unclassified HIGH 8.2
CVE-2026-65832

Deskflow is a keyboard and mouse sharing app. Prior to continuous build 1.26.0.299, a remote unauthenticated Deskflow server can send kMsgDSetOptions…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.6
CVE-2026-65822

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.116.0 and 16.23.0, erpnext/selling/report/inactive_customers/inactiv…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-65640

WordPress is vulnerable to a remote code execution vulnerability via malicious Postscript file upload by an Author level user or higher. Prerequisit…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 8.4
CVE-2026-64657

Budibase is an open-source low-code platform. Prior to 3.39.19, the PostgreSQL datasource connector in packages/server/src/integrations/postgres.ts i…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 8.2
CVE-2026-63409

Deskflow is a keyboard and mouse sharing app. From 1.17.0 until continuous build 1.26.0.296, a malicious Deskflow server can send an odd-length DSOP …

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-54356

Budibase is an open-source low-code platform. Prior to 3.41.3, POST /api/attachments/:datasourceId/url in packages/server/src/api/routes/static.ts an…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-54336

JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.17, an authenticated user wit…

Patch available
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-47698

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stacked indirection through Funct…

Patch available
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-47686

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, handleException() in lib/setup-sandbox.js sanitizes SuppressedError.error, SuppressedE…

Patch available
Fix from $5,750 2026-08-17
Unclassified HIGH 8.7
CVE-2026-47683

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, the bufferAllocLimit enforcement in lib/setup-sandbox.js does not cover Buffer.concat(…

Patch available
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-44846

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, a user with the users.invite_user…

Patch available
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.7
CVE-2026-44845

JumpServer is an open source bastion host and an operation and maintenance security audit system. Prior to 4.10.17, an authenticated administrator wi…

Patch available
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-39255

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, dup_…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-39254

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAu…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-40506

OpenEMR before 8.2.0 contains a path traversal vulnerability in the standard_tables_manage.php interface where the db GET parameter is passed without…

Patch available
Fix from $4,000 2026-08-17