Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

I CRITICAL 9.9
CVE-2026-18249

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from…

No fix yet
Fix from $2,300 2026-08-13
I CRITICAL 10.0
CVE-2026-18193

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses.

No fix yet
Fix from $2,300 2026-08-13
Documentation Offline CRITICAL 9.8
CVE-2026-17482

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths.

Fix: 1.5.1+
Fix from $2,300 2026-08-13
Documentation Offline CRITICAL 9.8
CVE-2026-17481

IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs.

Fix: 1.5.1+
Fix from $2,300 2026-08-13
I CRITICAL 9.6
CVE-2026-17101

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.9
CVE-2026-73656

Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-19747

A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fu…

No fix yet
Fix from $2,300 2026-08-13
I CRITICAL 9.8
CVE-2026-17206

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow.

Fix: after 7.6
Fix from $2,300 2026-08-13
I CRITICAL 9.8
CVE-2026-16961

IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker …

No fix yet
Fix from $2,300 2026-08-13
I CRITICAL 9.8
CVE-2026-16867

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au…

No fix yet
Fix from $2,300 2026-08-13
I CRITICAL 9.1
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b…

No fix yet
Fix from $2,300 2026-08-13
Websphere Application Server CRITICAL 9.4
CVE-2026-14525

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa…

Fix: 26.0.0.9+
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73653

Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta…

Patch available
Fix from $2,300 2026-08-13
I CRITICAL 9.8
CVE-2026-17197

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-73649

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-73644

OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-73567

sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-67614

CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-58508

Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-58443

Public-only repository tokens can update private PR head branches

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-58433

Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-56750

Gitea Remember-Me Token Theft Not Invalidating Attacker Session

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-56654

Privilege Escalation via Access Token Scope Escalation in API

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-56443

Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-55982

OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-13051

Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an …

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2022-4993

HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_er…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-73533

Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned upda…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-73532

Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned updat…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-53791

rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access contro…

No fix yet
Fix from $2,300 2026-08-13