Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cveclient HIGH 7.5
CVE-2026-35467

The stored API keys in temporary browser client is not marked as protected allowing for JavScript console or other errors to allow for extraction of …

Fix: 1.0.24+
Fix from $1,950 2026-04-02
Cveclient MEDIUM 6.1
CVE-2026-35466

XSS vulnerability in cveInterface.js allows for inject HTML to be passed to display, as cveInterface trusts input from CVE API services

Fix: 1.0.24+
Fix from $1,600 2026-04-02
Panda3d CRITICAL 9.8
CVE-2026-22189

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains a stack-based buffer overflow vulnerability due to use of an unbounde…

Fix: after 1.10.16
Fix from $2,300 2026-01-07
Panda3d HIGH 7.5
CVE-2026-22190

The egg-mkfont utility in Panda3D versions up to and including 1.10.16 contains an uncontrolled format string vulnerability. The -gp (glyph pattern) …

Fix: after 1.10.16
Fix from $1,950 2026-01-07
Panda3d MEDIUM 5.5
CVE-2026-22188

The deploy-stub component in Panda3D versions up to and including 1.10.16 contains a denial of service vulnerability due to unbounded stack allocatio…

Fix: after 1.10.16
Fix from $1,600 2026-01-07
Ghosts HIGH 7.5
CVE-2025-27092

GHOSTS is an open source user simulation framework for cyber experimentation, simulation, training, and exercise. A path traversal vulnerability was …

Fix: 8.2.7.90+
Fix from $1,950 2025-02-19
Opendiamond CRITICAL 9.3
CVE-2022-31506

The cmusatyalab/opendiamond repository through 10.1.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.

Fix: after 10.1.1
Fix from $2,300 2022-07-11
Carnegie Mellon Silicon Valley MEDIUM 5.4
CVE-2014-7723

The Carnegie Mellon Silicon Valley (aka edu.cmu.sv.mobile) application 0.1 for Android does not verify X.509 certificates from SSL servers, which all…

Mitigation only
Fix from $1,600 2014-10-21
Cyrus Imap Server HIGH 7.5
CVE-2011-3208EPSS 5%

Stack-based buffer overflow in the split_wildmats function in nntpd.c in nntpd in Cyrus IMAP Server before 2.3.17 and 2.4.x before 2.4.11 allows remo…

Fix: after 2.3.16
Fix from $1,950 2011-09-14
Cyrus Imap Server MEDIUM 5.1
CVE-2011-1926

The STARTTLS implementation in Cyrus IMAP Server before 2.4.7 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to i…

Fix: after 2.4.6
Fix from $1,600 2011-05-23
Dbd\ HIGH 7.5
CVE-2009-0663

Heap-based buffer overflow in the DBD::Pg (aka DBD-Pg or libdbd-pg-perl) module 1.49 for Perl might allow context-dependent attackers to execute arbi…

Patch available
Fix from $1,950 2009-04-30
Bootpd HIGH 10.0
CVE-1999-0799

Buffer overflow in bootpd 2.4.3 and earlier via a long boot file location.

Fix: after 2.4.3
Fix from $1,950 1997-06-01