Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-63293

A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-62420

An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project ins…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-19656

ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil…

No fix yet
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-17111

IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta…

No fix yet
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-17083

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow.

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.6
CVE-2026-73300

Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 10.0
CVE-2026-73299

Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .…

Patch available
Fix from $2,300 2026-08-12
I CRITICAL 9.9
CVE-2026-17276

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high…

Fix: after 7.6
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-17218

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write.

Fix: after 7.6
Fix from $2,300 2026-08-12
Db2 Mirror For I CRITICAL 9.8
CVE-2026-16956

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements…

Fix: after 7.6
Fix from $2,300 2026-08-12
I CRITICAL 9.9
CVE-2026-16860

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element.

Fix: after 7.6
Fix from $2,300 2026-08-12
GitLab CRITICAL 9.0
CVE-2026-16627

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an aut…

Fix: 19.2.2+
Fix from $2,300 2026-08-12
Allura CRITICAL 9.8
CVE-2026-73240

Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme…

Fix: 1.19.1+
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.4
CVE-2026-73296

Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and…

Patch available
Fix from $2,300 2026-08-12
I CRITICAL 9.8
CVE-2026-18847

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i.

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73294

Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controll…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.3
CVE-2026-64639

Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute …

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-73263

Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp au…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.4
CVE-2026-50561

Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authenti…

Patch available
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.1
CVE-2025-59324

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file i…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2025-59321

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows th…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.2
CVE-2026-67285

Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can p…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2025-59326

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned c…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-26035

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 10.0
CVE-2026-67282

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code …

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2025-41769

The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote atta…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.3
CVE-2026-66659

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18391

The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Orde…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-18366

The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress a…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.1
CVE-2026-16538

The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wall…

No fix yet
Fix from $2,300 2026-08-12