Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-77647 SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August 2026. This is related to inc… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.2 CVE-2026-77645 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill and PTC FlexPLM. The vulnerability may be exploited through t… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-77644 A critical bypass access control vulnerability has been reported in PTC Windchill Risk and Reliability (WRR) Enterprise Edition. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-72843 The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/updateCustomer/route.json, wh… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-69851 Server-side request forgery (ssrf) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-69836 Deserialization of untrusted data in Microsoft Entra ID allows an unauthorized attacker to execute code over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-69555 Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.6 CVE-2026-69400 Improper limitation of a pathname to a restricted directory ('path traversal') in Azure Logic Apps allows an unauthorized attacker to elevate privile… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-68789 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-68782 Improper neutralization of special elements used in an sql command ('sql injection') in Azure SQL Database allows an authorized attacker to elevate p… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-66309 Improper access control in Azure SQL Database allows an authorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-65816 Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-65801 Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 10.0 CVE-2026-65770 Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthori… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-63509 Relative path traversal in Microsoft Fabric allows an authorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-62834 Improper verification of cryptographic signature in Azure Data Factory allows an unauthorized attacker to elevate privileges over a network. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.4 CVE-2026-55769 CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and 1.29.2, CloudNativePG opened … Patch available Fix from $5,7502026-08-20 CRITICAL 9.9 CVE-2026-18835 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralizatio… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-17422 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to execute arbitrary code due to a buffer overflow. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17160 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow during size computat… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17157 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buffer overflow. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17152 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17145 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper privilege management. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17142 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to improper authentication. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17141 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17136 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format string vulnerability. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17122 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-based buffer overflow. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17118 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after-free vulnerability. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-17040 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer overflow. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-71485 Centrifugo is an open-source scalable real-time messaging server. Prior to 6.9.0, Centrifugo copies the client-controlled protocol.ConnectRequest.hea… Patch available Fix from $5,7502026-08-20