Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-39254 Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via the libSSEdevice.dylib, CxAu… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-68004 An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP publish authorization, vhost-lev… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-67678 File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-71472 A flaw was found in acm-search-v2-rhel9. This vulnerability allows an authenticated attacker, such as a hub administrator or a Search Custom Resource… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.4 CVE-2026-19478 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 bef… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.9 CVE-2026-66792 A flaw was found in the multicloud-operators-subscription component. This vulnerability allows a user on a managed cluster to escalate their privileg… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50775 A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an image from a crafted URL, an… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50774 An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role. No fix yet Fix from $5,7502026-08-17 CRITICAL 9.3 CVE-2026-74254 Joomla Extension - joomlack.fr - SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vulnerable to a SQL injection iss… No fix yet Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-74253 Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer befor… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50772 An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-51346 SQL Injection vulnerability in StudIP 6.0.x before 6.0.3 and 5.4.x before 5.4.12 allows a remote attacker to execute arbitrary code and obtain sensit… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50770 An issue in Squirro Cognitive Search before v.3.14.2 allows a remote attacker to escalate privileges via a crafted request. No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50769 The CRM+ application before and including version 2025.6 from Brainformatik is vulnerable to SQL Injection (time-based) vulnerability. The check conf… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-50768 File Upload vulnerability in T-Systems International GmbH ImageMaster Version: 9.14.2.8.1 allows a remote attacker to execute arbitrary code via the … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-75045 In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-71479 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image … Patch available Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-64859 New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and… Patch available Fix from $5,7502026-08-17 CRITICAL 9.3 CVE-2026-55674 Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.3 CVE-2026-71566 FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to valida… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.0 CVE-2026-14564 Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve … No fix yet Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-74843 A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttp… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74901 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74900 openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mo… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74899 openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74896 openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74895 openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can ex… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74894 openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74891 openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74889 openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and… No fix yet Fix from $5,7502026-08-17