Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-63293 A link following vulnerability in LXD allows an attacker to achieve arbitrary file read and write operations on the host system. When importing or un… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-62420 An authorization bypass vulnerability in LXD allows an authenticated attacker to bypass target project security restrictions during cross-project ins… Patch available Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-19656 ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privil… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17111 IBM i 7.6, 7.5, 7.4, and 7.3 s vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the atta… I No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17083 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. I No fix yet Fix from $2,3002026-08-12 CRITICAL 9.6 CVE-2026-73300 Budibase is an open-source low-code platform. Prior to 3.40.0, the MySQL integration component in Budibase is configured with multipleStatements: tru… No fix yet Fix from $2,3002026-08-12 CRITICAL 10.0 CVE-2026-73299 Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated untrusted .… Patch available Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-17276 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to escalate privileges due to improper authorization in the handling of high… I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-17218 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-16956 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to execute arbitrary commands due to improper neutralization of special elements… Db2 Mirror For I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-16860 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to execute arbitrary code due to an uncontrolled search path element. I after 7.6 Fix from $2,3002026-08-12 CRITICAL 9.0 CVE-2026-16627 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.2 that under certain conditions could have allowed an aut… GitLab 19.2.2+ Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-73240 Specifically crafted inputs may lead to git argument injection in Apache Allura. This issue affects Apache Allura: before 1.19.1. Users are recomme… Allura 1.19.1+ Fix from $2,3002026-08-12 CRITICAL 9.4 CVE-2026-73296 Microsoft UFO open-source framework for intelligent automation across devices and platforms. Prior to 3.0.8, create_mobile_data_collection_server and… Patch available Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-18847 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote unauthenticated attacker to harvest credentials due to spoofing of Navigator for i. I No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-73294 Semaphore UI is a web interface for managing DevOps tools. Prior to 2.18.17 and 2.19.5-beta2, repository git_url handling passes an attacker-controll… Patch available Fix from $2,3002026-08-12 CRITICAL 9.3 CVE-2026-64639 Incorrect database cloning process in Plesk from 18.0.52 before 18.0.79.6 and 18.0.80.2 allows a low-privileged user (customer, reseller) to execute … No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-73263 Prowler is a cloud security platform. Prior to 5.36.0, the Kubernetes provider connection test accepted kubeconfig_content containing a legacy gcp au… Patch available Fix from $2,3002026-08-12 CRITICAL 9.4 CVE-2026-50561 Yuxi is a large-model-based intelligent knowledge base and knowledge graph agent development platform. Prior to version 0.6.2, the project's authenti… Patch available Fix from $2,3002026-08-12 CRITICAL 9.1 CVE-2025-59324 CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to properly validate LUKS encryption and, if encryption is present, all CryptoPro file i… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2025-59321 CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 contains a default TPM PCR policy that fails to consider the system boot state. This allows th… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.2 CVE-2026-67285 Joomla Extension - joomshaper.com - Unauthenticated arbitrary local PHP file inclusion in SP Page Builder < 6.8.0 - An unauthenticated attacker can p… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2025-59326 CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned c… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-26035 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4… No fix yet Fix from $2,3002026-08-12 CRITICAL 10.0 CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code … No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2025-41769 The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote atta… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.3 CVE-2026-66659 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-18391 The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not validate user input before unserializing it on stores with High-Performance Orde… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-18366 The Events Manager WordPress plugin before 7.4.1 does not properly scope its capability mapping, discarding the access control decisions WordPress a… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.1 CVE-2026-16538 The Wallet for WooCommerce WordPress plugin before 1.6.10 does not verify the amount actually collected for a wallet top-up before crediting the wall… No fix yet Fix from $2,3002026-08-12