Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-9190 An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypa… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.9 CVE-2026-8709 An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows … Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-8400 IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in I… Websphere Application Server No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-7557 An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.9 CVE-2026-7329 An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-60053 Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u… Answer 2.0.2+ Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-16442 A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $2,3002026-08-05 CRITICAL 9.4 CVE-2026-15587 Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to… Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-10025 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne… Qradar Security Information And Event Manager No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-16443 A flaw was found in the SAML metadata import functionality of the keycloak-services component, which is the core engine for identity brokering in Red… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71289 The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service'… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71278 rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. Th… Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71277 rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never … No fix yet Fix from $2,3002026-08-05 CRITICAL 9.9 CVE-2026-71268 OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes t… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71267 microtar's mtar_write_file_header and mtar_write_dir_header functions (src/microtar.c) copy a caller-supplied entry name into the 100-byte field of a… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71263 The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71262 IoTSharp BlobStorageController.cs lacks the [Authorize] attribute applied to every other controller in the application (DevicesController, CustomersC… Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71256 nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71254 nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in … No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71248 Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f… Patch available Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71238 DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71237 Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71231 IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-66747 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-44945 A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w… Patch available Fix from $2,3002026-08-05 CRITICAL 9.0 CVE-2026-10090 A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-10059 A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71214 The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraS… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71213 Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when capt… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71207 The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly… No fix yet Fix from $2,3002026-08-05