Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 10.0
CVE-2026-61539

Xinference is an inference API for running open-source, speech, and multimodal models. In 2.5.0 and earlier, Xinference passes attacker-influenced Ll…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.2
CVE-2026-59989

Phalcon is a high-performance, full-stack PHP framework. In 5.15.0 and earlier, resolveFilter in phalcon/Mvc/View/Engine/Volt/Compiler.zep builds the…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-77810

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the co…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.0
CVE-2026-62674

Omnigent is an open-source AI agent framework and meta-harness for orchestrating coding agents. Prior to 0.3.0, PUT /sessions/{session_id}/agent chec…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 10.0
CVE-2026-69502

Server-side request forgery (ssrf) in Azure SQL Database allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.4
CVE-2026-77812

DJI drones transmit DUML (DJI Universal Markup Language) protocol messages over BLE (Bluetooth Low Energy) without encryption. When a client attempts…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.6
CVE-2026-77087

Paperclip before 0.3.1 in default local_trusted mode fails to validate Host headers, allowing attackers to execute arbitrary commands via DNS rebindi…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-63343

Incus is a system container and virtual machine manager. Prior to version 7.3.0, a malicious image containing a `metadata.yaml` symlink pointing to a…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-63125

Incus is a system container and virtual machine manager. Prior to version 7.3.0, an unprivileged, project-confined Incus user (a non-admin TLS/RBAC i…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62941

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when copying an instance across projects, the project restriction ch…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62940

Incus is a system container and virtual machine manager. Prior to version 7.3.0, when migrating an instance to another cluster member, user-supplied …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62867

Incus is a system container and virtual machine manager. Prior to version 7.3.0, improper validation of user-provided `block.create_options` in stora…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48769

Incus is a system container and virtual machine manager. Prior to version 7.2.0, an arbitrary file write exists in the Incus client when a malicious …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48755

Incus is a system container and virtual machine manager. Prior to version 7.1.0, improper validation of user-provided backup compression algorithm le…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48753

Incus is a system container and virtual machine manager. Prior to version 7.1.0, the S3 protocol upload endpoint is vulnerable to path traversal and …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48752

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image or instance backup can be used to read or …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48751

Incus is a system container and virtual machine manager. Prior to version 7.2.0, instance snapshots ignore the `restricted.containers.lowlevel=block`…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48750

Incus is a system container and virtual machine manager. Prior to version 7.2.0, the `record-output` parameter of the `/instances/$name/exec` endpoin…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-48749

Incus is a system container and virtual machine manager. Prior to version 7.2.0, a specially crafted image can be used to read or create/write arbitr…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77806

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to cod…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-77776

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/p…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-77683

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-77086

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to …

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-76158

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacke…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.4
CVE-2026-76156

OS command injection in the api endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows an authenticated administrator to execut…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-76155

Use of default credentials in Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacker to gain administrative access to the…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depen…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate, because it has a rogue depe…

No fix yet
Fix from $5,750 2026-08-21