Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-74874

openssl_encrypt versions before 1.4.0 use Python's non-cryptographic random module for steganographic pixel selection in the generate_pseudorandom_se…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-74873

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings accessible to all system users. Att…

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74872

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob pat…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-74871

openssl_encrypt versions before 1.4.6 contain a key derivation flaw in sequential XOR composition mode where the last stage cancels out during key ge…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 7.7
CVE-2026-74869

stoatchat before 0.15.0 contains a missing authorization vulnerability in the Subscribe message handler that allows authenticated attackers to enumer…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 7.5
CVE-2026-74868

SiYuan versions before 3.7.4 contain an unthrottled brute-force vulnerability in the Publish Service Basic Auth implementation (PublishServiceTranspo…

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-74842

A vulnerability was found in Kira-Pgr PromptShopMCP up to 5bc0cd17358e19a5415d11a531088170d7b81452. Affected is the function download_image of the fi…

No fix yet
Fix from $4,000 2026-08-17
Unclassified HIGH 8.2
CVE-2026-74802

SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disa…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 8.2
CVE-2026-74801

SiYuan before 3.7.4 fails to properly escape workspace directory paths when constructing command-line arguments for the elevated elevator.exe helper …

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.0
CVE-2026-74800

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-si…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-74799

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set…

No fix yet
Fix from $5,750 2026-08-17
Unclassified HIGH 8.7
CVE-2026-74798

SiYuan kernel before v3.7.4 contains a path traversal vulnerability in the database_clean MCP tool. The tool performs only an empty-string check on t…

No fix yet
Fix from $4,900 2026-08-17
Unclassified HIGH 8.8
CVE-2026-74845

Official Document Management System developed by 2100 Technology has an Arbitrary File Upload vulnerability, allowing authenticated remote attackers …

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 5.5
CVE-2026-49308

Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49307

Permission control vulnerability in the multi-mode input module. Impact: Successful exploitation of this vulnerability may affect service confidentia…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49305

Permission control vulnerability in the Wi-Fi enhancement module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49304

Permission control vulnerability in the device key management module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.1
CVE-2026-49303

Permission control vulnerability in the notification module. Impact: Successful exploitation of this vulnerability may affect availability.

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49302

Permission control vulnerability in the notification service module. Impact: Successful exploitation of this vulnerability may affect service confide…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.2
CVE-2026-49301

Permission control vulnerability in the Gallery module. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-20000

A vulnerability was detected in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewprescriptio…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19999

A security vulnerability has been detected in Open Asset Import Library Assimp Assimp 17c12da. The affected element is the function Assimp::MDLImport…

Patch available
Fix from $4,000 2026-08-17
Unclassified HIGH 8.3
CVE-2026-22072

Loading arbitrary external URLs through WebView components introduces malicious JS code that can steal arbitrary user tokens.

No fix yet
Fix from $4,900 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19994

A vulnerability was found in Webkul Bagisto up to 2.4.4. Affected by this issue is some unknown functionality of the file /admin/configuration/cache-…

No fix yet
Fix from $4,000 2026-08-17
Unclassified CRITICAL 9.4
CVE-2026-15623

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Clou…

No fix yet
Fix from $5,750 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-19987

A security vulnerability has been detected in SourceCodester Best Employee Management System 1.0. This affects an unknown function of the file /asset…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.3
CVE-2026-14832

The ShopSmart Loyalty for WooCommerce WordPress plugin through 1.0.0 does not perform any authorization or ownership check on a phone-number lookup e…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.9
CVE-2026-13700

The WooMS WordPress plugin through 9.14 does not validate a user-supplied URL before using it in a server-side request and attaches stored third-part…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 5.4
CVE-2026-19986

A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the function updateDynamicRules of the…

No fix yet
Fix from $4,000 2026-08-17
Unclassified MEDIUM 6.3
CVE-2026-19984

A flaw has been found in jkawamoto mcp-florence2 up to 0.3.13. Affected by this issue is the function get_images of the file src/mcp_florence2/__init…

No fix yet
Fix from $4,000 2026-08-17