Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-59503 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor No fix yet Fix from $2,3002026-08-13 CRITICAL 10.0 CVE-2026-59500 CWE-287: Improper Authentication No fix yet Fix from $2,3002026-08-13 CRITICAL 10.0 CVE-2026-15413 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-14182 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-16770 PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file… Patch available Fix from $2,3002026-08-13 CRITICAL 9.6 CVE-2026-71193 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.6 CVE-2026-49481 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-73519 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs,… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.1 CVE-2026-73501 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently r… Patch available Fix from $2,3002026-08-12 CRITICAL 9.0 CVE-2026-71471 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search … No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-18749 The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac… Patch available Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-10534 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. Db2 after 12.1.5 Fix from $2,3002026-08-12 CRITICAL 10.0 CVE-2024-27253 IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-66898 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing … No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-19001 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, sche… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17616 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access 10.0.9.2 / 11.0.3+ Fix from $2,3002026-08-12 CRITICAL 9.6 CVE-2026-13433 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an I… I Access Client Solutions 1.1.9.14+ Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-10543 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. Db2 after 12.1.5 Fix from $2,3002026-08-12 CRITICAL 9.2 CVE-2026-73414 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`… Patch available Fix from $2,3002026-08-12 CRITICAL 9.0 CVE-2026-73407 Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials … Patch available Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-73269 A flaw was found in the cluster-curator-controller component. A local user, by creating a ClusterCurator resource with a specific naming convention, … No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-73268 A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurat… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-72508 A flaw was found in the multicloud-operators-subscription component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a names… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-63300 An improper validation vulnerability in the instancePostMigration function in lxd/instance_post.go of LXD allows an authenticated attacker with can_c… Patch available Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-63299 An authorization bypass vulnerability in LXD allows an authenticated user to bypass project-level disk and volume limits. Two related code paths fail… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-63298 An improper neutralization of special elements vulnerability in LXD's NVIDIA instance configuration handling allows an authenticated attacker to inje… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-63297 An authorization bypass vulnerability in LXD due to a timing flaw during configuration merging allows an authenticated attacker to bypass target proj… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-63296 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project restrictions during instance migration. When m… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-63294 A link following vulnerability in LXD allows an attacker to achieve root command execution on the host system. During the import or unpacking of craf… No fix yet Fix from $2,3002026-08-12