Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-71879

Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 all…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.2
CVE-2026-71878

Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-67921

Cross-Site Request Forgery (CSRF) vulnerability exists in Halo CMS versions up to 2.25.4 via the CorsConfigurer.java and the CsrfConfigurer.java comp…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-66780

A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-52610

An arbitrary file write/directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to create or overwrite files anywhere on …

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitrary php code into the PreExecu…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-50161

libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in …

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2021-43717

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection function, you can access the…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2021-43716

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted f…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-67271

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with remote access could potentiall…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.4
CVE-2026-57580

authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, an inbound SAML Source configured with the non-default USERNAME_LINK o…

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-52723

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3…

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-18963

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-75913

CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-sup…

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-45118

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-45117

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura…

Patch available
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-12564

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 10.0
CVE-2026-75784

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx …

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73996

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73397

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73392

Unauthenticated SQL Injection in Super Store Finder <= 7.8 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-73381

Unauthenticated Broken Authentication in Popup by Supsystic <= 1.13.0 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73380

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73376

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73365

Unauthenticated SQL Injection in JetAppointment <= 2.5.2 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73355

Unauthenticated SQL Injection in Affiliates Manager <= 2.9.53 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 10.0
CVE-2026-73343

Unauthenticated Remote Code Execution (RCE) in WP Compress < 7.20.01 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

No fix yet
Fix from $5,750 2026-08-18