Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-68154

In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserv…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68144

In the Linux kernel, the following vulnerability has been resolved: phonet: pep: fix use-after-free in pep_get_sb() pep_get_sb() doesn't consider t…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68137

In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free in x25_kill_by_neigh() x25_kill_by_neigh() walks th…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68136

In the Linux kernel, the following vulnerability has been resolved: net: gro: fix double aggregation of flush-marked skbs Commit 0ab03f353d36 ("net…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68127

In the Linux kernel, the following vulnerability has been resolved: ila: reload IPv6 header after pskb_may_pull in checksum adjust ila_csum_adjust_…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-68124

In the Linux kernel, the following vulnerability has been resolved: mctp: serial: handle zero-length frames to prevent rx buffer overflow The MCTP …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68123

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC curre…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-68117

In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk…

No fix yet
Fix from $2,300 2026-08-10
Enterprise Linux CRITICAL 9.9
CVE-2026-59090

A flaw was found in GIMP's PSD file format plugin. This vulnerability, an unsigned integer underflow in the `block_rem` variable, occurs when a user …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-13206

Improper neutralization of special elements used in an OS command ('OS command injection') vulnerability in Zyxel Networks WAH7601 allows OS Command …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-68083

In the Linux kernel, the following vulnerability has been resolved: ksmbd: fix path resolution in ksmbd_vfs_kern_path_create The SMB2 open lookup i…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72593

A missing authentication vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to access the full file manager func…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72592

An unrestricted file upload vulnerability in dulldusk/phpfm through 1.8.0 allows an unauthenticated remote attacker to execute arbitrary PHP code on …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72590

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to inject arbitrary cron job…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72589

An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to execute arbitrary system …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72580

An OS command injection vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker to execute arbitrary system commands on X…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72577

Multiple vulnerabilities in NASA fprime-gds through 3.4.3 allow an unauthenticated remote attacker to achieve arbitrary code execution on the ground …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-72575

An improper authorization vulnerability in daptin through v0.12.34 allows unauthenticated remote attackers to read, create, update, and delete usergr…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.1
CVE-2026-72569

A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72567

An improper path validation vulnerability in AsyncFuncAI/deepwiki-open through commit 16f35a0 allows unauthenticated remote attackers to write to or …

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-72565

A SQL injection vulnerability in Tencent APIJSON through 8.1.8 allows unauthenticated remote attackers to bypass per-table access control and read ar…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.6
CVE-2026-72564

An improper authorization vulnerability in fosrl/pangolin through v1.20.0 allows an authenticated remote attacker to authenticate to any resource in …

No fix yet
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-55799

Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fi…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-44416

Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgra…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-42537

Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-40920

Privilege Escalation via URL Parameter is reported in Apache Ranger versions <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixe…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-32227

SQL Injection vulnerability vulnerability in Apache Ranger. This issue affects . Users are recommended to upgrade to version 2.9.0, which fixes the…

Fix: 2.9.0+
Fix from $2,300 2026-08-10
Ranger CRITICAL 9.8
CVE-2026-28672

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Ranger. This issue affects Apache Ranger…

Fix: after 2.8.0
Fix from $2,300 2026-08-10
Unclassified CRITICAL 10.0
CVE-2026-66915

Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by using the aja…

No fix yet
Fix from $2,300 2026-08-10
Unclassified CRITICAL 9.8
CVE-2026-19089

The Product Input Fields for WooCommerce WordPress plugin before 2.0.2 does not validate uploaded file types when its accepted-types setting is left …

No fix yet
Fix from $2,300 2026-08-10