Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-18249 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to gain elevated privileges due to improper validation of pointers read from… I No fix yet Fix from $2,3002026-08-13 CRITICAL 10.0 CVE-2026-18193 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of user-controlled addresses. I No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-17482 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper control of file paths. Documentation Offline 1.5.1+ Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-17481 IBM Documentation Offline 1.0.0 through 1.4.1 could allow a remote attacker to execute arbitrary code due to improper output neutralization for logs. Documentation Offline 1.5.1+ Fix from $2,3002026-08-13 CRITICAL 9.6 CVE-2026-17101 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code or obtain sensitive information due to improper authentication. I No fix yet Fix from $2,3002026-08-13 CRITICAL 9.9 CVE-2026-73656 Trigger.dev is a platform for building and deploying fully managed AI agents and workflows. Prior to 4.5.6, POST /api/v1/deployments/:deploymentId/ba… Patch available Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-19747 A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20260625. This impacts the fu… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-17206 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a buffer overflow. I after 7.6 Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-16961 IBM i 7.6, 7.5, and 7.4 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker … I No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-16867 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to access server resources with the privileges of an authenticated user due to improper au… I No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-16815 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive information due to a stack-b… I No fix yet Fix from $2,3002026-08-13 CRITICAL 9.4 CVE-2026-14525 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 IBM WebSphere Application Server Liberty is vulnerable to an authentication bypa… Websphere Application Server 26.0.0.9+ Fix from $2,3002026-08-13 CRITICAL 9.4 CVE-2026-73653 Vitest is a testing framework powered by Vite. Prior to versions 3.2.7, 4.1.10, and 5.0.0-beta.6, Browser Mode provider commands including upload, ta… Patch available Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-17197 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to bypass security restrictions due to improper validation of client-asserted identity. I No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-73649 Velocity.js is a JavaScript implementation of the Apache Velocity template engine. Prior to 2.1.7, the earlier fix for CVE-2026-44966 filtered constr… Patch available Fix from $2,3002026-08-13 CRITICAL 9.6 CVE-2026-73644 OpenDJ is an LDAPv3 compliant directory service. Prior to 5.1.2, the SASL PLAIN authorization identity path in opendj-server-legacy/src/main/java/org… Patch available Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-73567 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.… Patch available Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-67614 CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-58508 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-58443 Public-only repository tokens can update private PR head branches No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-56750 Gitea Remember-Me Token Theft Not Invalidating Attacker Session No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-56654 Privilege Escalation via Access Token Scope Escalation in API No fix yet Fix from $2,3002026-08-13 CRITICAL 9.6 CVE-2026-56443 Token public-only scope bypassed on Limited-visibility owners (Repository + Package categories) — residual after CVE-2026-25714 / PR #37118 No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-55982 OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-13051 Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 for Perl allow attacker selected method dispatch and resource exhaustion via an … Patch available Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2022-4993 HTML::FormHandler versions through 0.40068 for Perl allow attacker selected method dispatch and resource exhaustion because _apply_actions and add_er… Patch available Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-73533 Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned upda… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-73532 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned updat… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-53791 rsync daemon before 3.5.0 contains an IP address spoofing vulnerability that allows unauthenticated remote attackers to bypass IP-based access contro… No fix yet Fix from $2,3002026-08-13