Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-35219

Budibase is an open-source low-code platform. Prior to 3.41.3, automation steps in packages/server/src/automations/steps/outgoingWebhook.ts, packages…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.0
CVE-2026-34789

FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, src/App/PropertyPythonObject.cpp in PropertyPythonObject::Rest…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.8
CVE-2026-34399

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, FreeCAD's BIM Workbench contains an eval() call on untr…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.8
CVE-2026-34398

FreeCAD is a free and open-source multiplatform 3D parametric modeler. From 0.19 until 1.1.1, src/Mod/BIM/bimcommands/BimProjectManager.py in the BIM…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.1
CVE-2026-19589

Packer up to 1.15.4 is vulnerable to an issue in the third-party plugin installer that may allow unintended file system modification and could lead t…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.3
CVE-2026-75014

A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. This vulnerability affects unknown code of the file /admin/get_barcode_…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75013

A vulnerability was detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. This affects the function setWizardCfg of the file /cgi-bin/cstecgi.cgi. The …

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-75012

A security vulnerability has been detected in TOTOLINK EX1200L 9.3.5u.6146_B20201023. Affected by this issue is the function setPasswordCfg of the fi…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.7
CVE-2026-74234

Legora before 2026-08-14 contains a cross-site scripting vulnerability that allows attackers to achieve arbitrary JavaScript execution in a victim's …

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-71858

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, macros loaded from an attacker-controlled shortcuts.xml bypass the HMAC valid…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 7.1
CVE-2026-71553

ApostropheCMS is an open-source Node.js content management system. In 4.32.0 and earlier, PATCH /api/v1/article/:id accepts the inherited path toStri…

Patch available
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-68004

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-lev…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67678

File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-71472

A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 8.8
CVE-2026-70495

A flaw was found in search-v2-operator. This component's `search-serviceaccount` has overly broad permissions, allowing it to impersonate users and g…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-68005

An issue in ACME mini_httpd 1.30 and prior allows a remote attacker to cause a denial of service via the HTTP request header parser in the handle_req…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.1
CVE-2026-63670

ApostropheCMS is an open-source Node.js content management system. Prior to 2.17.6, sanitizeHtml() can pass disallowed executable markup through pack…

Patch available
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-63669

ApostropheCMS is an open-source Node.js content management system. Prior to 4.32.0, the page module's move() operation fails to enforce the destinati…

Patch available
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.5
CVE-2026-63667

ApostropheCMS is an open-source Node.js content management system. Prior to 3.6.2, the import-export module in packages/import-export/lib/formats/gzi…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 8.5
CVE-2026-57485

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /api/v1/pipeline/handleData en…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 8.1
CVE-2026-57233

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the WinGup decompress function joins untrusted ZIP entry names to unzipDestTo…

Patch available
Fix from $4,900 2026-08-17
Unclassified HIGH 7.8
CVE-2026-54758

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, the expandNppEnvironmentStrs function in PowerEditor/src/WinControls/StaticDi…

Patch available
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.1
CVE-2026-52886

Notepad++ is a free and open-source source code editor. Prior to 8.9.7, Notepad++ validates the backupFilePath attribute from session.xml with std::w…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 7.1
CVE-2026-19650

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.4
CVE-2026-19478

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-75011

A flaw has been found in kylecui NetForensicMCP 2.1.0. Impacted is the function execAsync of the file index.js. Executing a manipulation of the argum…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.5
CVE-2026-74238

TIER IV Nebula through 1.2.0 contains an out-of-bounds read vulnerability in the Vlp32Decoder::unpack() function that allows unauthenticated remote a…

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-66792

A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileg…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 7.5
CVE-2026-50776

Directory Traversal vulnerability in Pronis Loisirs Billetterie CSE - < 04/2026 allows a remote attacker to obtain sensitive information and execute …

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-50775

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, an…

No fix yet
Fix from $5,750 2026-08-17