Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-73046

SiYuan before v3.7.4 improperly restricts excessive authentication attempts in the CheckAuth() middleware. The HTTP Basic Authentication branch, whic…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73044

SiYuan versions before v3.7.4 fail to validate or escape table column width values, allowing stored cross-site scripting injection into style attribu…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73043

SiYuan versions before v3.7.4 contain a remote code execution vulnerability in the Template calculation operator, which renders user-authored Go temp…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73042

SiYuan before v3.7.4 fails to properly escape database menu metadata in HTML interpolation, allowing stored values to execute script when users open …

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73041

SiYuan versions before v3.7.4 fail to validate or escape annotation fields written to disk by the setFileAnnotation endpoint. Attackers can inject ma…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.1
CVE-2026-18855

The Link Library plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the ll_delete_link_fields …

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-19598

The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Privilege Escalation via Authorization Bypass in all versions up to,…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-15689

Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow password reset link poisoning via the request Host header in _default_email_p…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.3
CVE-2026-74573

In the Linux kernel, the following vulnerability has been resolved: iommu/arm-smmu-v3-iommufd: Require exactly one Stream ID for a vDEVICE arm_vsmm…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74570

In the Linux kernel, the following vulnerability has been resolved: ntfs: harden runlist realloc size calculations Add a shared helper to safely co…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74569

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() s…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.3
CVE-2026-74568

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Fix race between LPI release and re-registration Fix a potent…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74556

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer i…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74545

In the Linux kernel, the following vulnerability has been resolved: rtase: fix double free of multi-frag skb on DMA map failure In rtase_start_xmit…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.1
CVE-2026-74521

In the Linux kernel, the following vulnerability has been resolved: ksmbd: use memcmp() to compare ClientGUIDs ClientGUID is a fixed-size binary va…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.3
CVE-2026-74517

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Cancel delayed I/O APIC EOI handling before destroying vCPUs Cancel (…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74495

In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error cleanup If an error is encountered while mappin…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74493

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix socket use-after-free during link group termination __smc_lgr_term…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74480

In the Linux kernel, the following vulnerability has been resolved: net: bridge: stop fast-leave after deleting a port group br_multicast_leave_gro…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74478

In the Linux kernel, the following vulnerability has been resolved: um: vector: fix use-after-free in vector_mmsg_rx() When vector_mmsg_rx() discar…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.1
CVE-2026-74476

In the Linux kernel, the following vulnerability has been resolved: veth: convert frag_list skbs before running XDP A frag_list skb can reach veth …

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 10.0
CVE-2026-74475

In the Linux kernel, the following vulnerability has been resolved: vxlan: use neigh_ha_snapshot() in route_shortcircuit() The neighbour hardware a…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74474

In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() for transmit path header pulls In vxlan_xmit…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74473

In the Linux kernel, the following vulnerability has been resolved: vxlan: use pskb_network_may_pull() in route_shortcircuit() route_shortcircuit()…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.1
CVE-2026-73194

DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an unvalidated numeric placeholder that sets the binder counter in preparse. …

Patch available
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-73193

DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit perl via an integer wraparound in the output buffer size computed by pr…

Patch available
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-16142

The TrueBooker plugin for WordPress is vulnerable to Account Takeover in all versions up to, and including, 1.2.6. This is due to the add_front_user_…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-15826

The User Profile Builder plugin for WordPress is vulnerable to Authentication Bypass via Type Confusion in versions up to, and including, 3.16.4. Thi…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.3
CVE-2026-74439

In the Linux kernel, the following vulnerability has been resolved: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry d…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.8
CVE-2026-74436

In the Linux kernel, the following vulnerability has been resolved: rxrpc: serialize kernel accept preallocation with socket teardown rxrpc_kernel_…

No fix yet
Fix from $5,750 2026-08-15