Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-12366 Zephyr's dynamic kernel-object disposal path unref_check() in kernel/userspace/userspace.c frees an object's storage (k_free(dyn->data)) once its ref… Patch available Fix from $4,9002026-08-14 MEDIUM 5.8 CVE-2026-12365 A use-after-free exists in the Zephyr second-generation work queue (kernel/work.c) in the handling of delayable work timeouts. When a delayable work … Patch available Fix from $4,0002026-08-14 HIGH 8.4 CVE-2026-12364 The user-space system-call verifier z_vrfy_z_log_msg_static_create() in subsys/logging/log_msg.c was a pure pass-through: it forwarded the caller-sup… Patch available Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-73846 CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, canonicalizeParams in src/utils/cache.ts serializes request paramete… Patch available Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-73845 CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, the ckan_get_mqa_quality and ckan_get_mqa_quality_details tools in s… Patch available Fix from $4,0002026-08-14 HIGH 7.1 CVE-2026-49989 CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3.2, any authenticated user can read or delete any blob whose SHA-1 digest they … No fix yet Fix from $4,9002026-08-14 HIGH 7.1 CVE-2026-49986 The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persistent memory MCP, prior to version 3.17.1 treats the `CLAUDE_PROJECT_DIR` enviro… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.1 CVE-2026-47766 crun is an open source OCI Container Runtime fully written in C. Prior to version 1.28, crun's default device setup opens the container rootfs `/dev`… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-46603 VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amount of memory when processing a crafted VP8L image containing many unused Huffm… No fix yet Fix from $4,9002026-08-14 HIGH 7.8 CVE-2026-46439 compliance-trestle is a tooling platform for managing compliance as code. Versions prior to 3.12.2 and 4.0.3 have a Server-Side Template Injection (S… Patch available Fix from $4,9002026-08-14 MEDIUM 6.7 CVE-2026-46380 compliance-trestle is a tooling platform for managing compliance as code. Prior to versions 3.12.2 and 4.0.3, the HTTPSFetcher._do_fetch() method pas… Patch available Fix from $4,0002026-08-14 HIGH 8.8 CVE-2026-19845 A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function setStaticDhcpConfig of the file /cgi-bin/cstecgi.c… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19844 A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setRadvdCfg of the file /cgi-bin/cstecgi.cgi… No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-19628 A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to … Security Center 6.9.0+ Fix from $4,9002026-08-14 CRITICAL 9.9 CVE-2026-19626 A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user … Security Center 6.9.0+ Fix from $5,7502026-08-14 MEDIUM 5.3 CVE-2026-66272 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Missing Authentication for Critical Function vulnerability. An unauthenticate… Wyse Management Suite 2605.0.2+ Fix from $4,0002026-08-14 HIGH 7.2 CVE-2026-66271 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil… Wyse Management Suite 2605.0.2+ Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-66270 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Unrestricted Upload of File with Dangerous Type vulnerability. A high privil… Wyse Management Suite 2605.0.2+ Fix from $4,9002026-08-14 MEDIUM 5.5 CVE-2026-63702 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain a Use of Hard-coded Credentials vulnerability. A low privileged attacker with l… Wyse Management Suite 2605.0.2+ Fix from $4,0002026-08-14 HIGH 7.8 CVE-2026-63701 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Improper Deserialization of Untrusted Data vulnerability. A low privileged a… Wyse Management Suite 2605.0.2+ Fix from $4,9002026-08-14 HIGH 7.8 CVE-2026-63700 Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain an Incorrect Default Permission vulnerability. A low privileged attacker with l… Wyse Management Suite 2605.0.2+ Fix from $4,9002026-08-14 MEDIUM 6.9 CVE-2026-57472 Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.8 CVE-2026-57471 Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in the file ma… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.1 CVE-2026-57469 Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery (CSRF) vulnerability in the web-based configuration backend of KUNBUS PiCtory i… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-53970 ZeroBrew version 0.3.1 and prior contains a missing integrity verification vulnerability in the Ruby compatibility shim that allows network attackers… Patch available Fix from $4,9002026-08-14 HIGH 8.4 CVE-2026-19884 In Eclipse Theia versions up to and including 1.69.0, opening a folder starts source control integration without requiring the user to trust the fold… Patch available Fix from $4,9002026-08-14 HIGH 8.1 CVE-2026-16772 In Akaunting versions <= 3.1.21, low‑privileged authenticated users can modify their own account to assign themselves the admin role ID, granting ful… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.9 CVE-2026-13198 Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability … No fix yet Fix from $4,0002026-08-14 HIGH 7.3 CVE-2026-13197 Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability … No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-13196 Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in ver… No fix yet Fix from $4,9002026-08-14