Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-59503

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-59500

CWE-287: Improper Authentication

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-15413

The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-14182

The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49819

UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-16770

PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-71193

In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.6
CVE-2026-49481

UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-73519

WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs,…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.1
CVE-2026-73501

kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently r…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.0
CVE-2026-71471

A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search …

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18749

The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac…

Patch available
Fix from $2,300 2026-08-12
Db2 CRITICAL 9.8
CVE-2026-10534

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser.

Fix: after 12.1.5
Fix from $2,300 2026-08-12
Unclassified CRITICAL 10.0
CVE-2024-27253

IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities.

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-66898

A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing …

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-19001

The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, sche…

No fix yet
Fix from $2,300 2026-08-12
Security Verify Access CRITICAL 9.8
CVE-2026-17616

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr…

Fix: 10.0.9.2 / 11.0.3+
Fix from $2,300 2026-08-12
I Access Client Solutions CRITICAL 9.6
CVE-2026-13433

IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an I…

Fix: 1.1.9.14+
Fix from $2,300 2026-08-12
Db2 CRITICAL 9.8
CVE-2026-10543

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query.

Fix: after 12.1.5
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.2
CVE-2026-73414

Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.0
CVE-2026-73407

Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials …

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73269

A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, …

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73268

A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-72508

A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a names…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63300

An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_c…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63299

An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63298

An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63297

An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63296

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-63294

A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf…

No fix yet
Fix from $2,300 2026-08-12