Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.7 CVE-2026-69101 Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request … Patch available Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-58224 A flaw was found in Samba's CTDB, the clustered database service used by Samba. Insufficient integrity validation of received CTDB protocol packets a… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19880 Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (logback-classic module) allows path-traversal vulnerability. More specifically, … No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-19879 A flaw was found in Undertow, an HTTP server, within its HTTP response header writing path. The `writeString()` method performs a silent narrowing ca… No fix yet Fix from $4,0002026-08-14 HIGH 7.5 CVE-2026-73633 Uncontrolled resource consumption vulnerability in the JSON plugin of Apache Struts. When an application is configured to populate actions from a JSO… Struts 6.11.0 / 7.3.0+ Fix from $4,9002026-08-14 MEDIUM 6.3 CVE-2026-53472 A flaw was found in migration-planner. Insufficient validation of the `AgentStatusUpdate.CredentialUrl` field allows an authenticated attacker to sto… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-1621 Authentication bypass by primary weakness vulnerability in Universal Software Inc. E-Municipality allows Exploitation of Trusted Identifiers. This i… No fix yet Fix from $4,0002026-08-14 CRITICAL 9.3 CVE-2026-19871 Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to a… Patch available Fix from $5,7502026-08-14 MEDIUM 5.3 CVE-2026-19830 A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1B028-US.EN. This impacts an unknown function of the file /etc/bftpd.conf of the… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19828 A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-20260107. This affects an unknown part of the file PlayController.java of the compo… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.3 CVE-2026-19827 A flaw has been found in alldatacenter alldata up to 0.6.8. This impacts the function FileInputStream of the file /admin/controller/JobLogController.… No fix yet Fix from $4,0002026-08-14 HIGH 8.1 CVE-2026-19768 Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an … No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-73673 Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated firmware update vulnerability that allows unauthenticated attackers to submit unsi… No fix yet Fix from $4,9002026-08-14 HIGH 8.6 CVE-2026-19870 Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding … Patch available Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19826 A vulnerability was detected in alldatacenter alldata up to 0.6.8. This affects the function Hessian2Input.readObject of the file /serialize/impl/Hes… No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19825 A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the … No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19824 A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. The affected element is the function ipMacBindListStore of the file /go… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19823 A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. Impacted is the function formQOSRuleDel of the file /goform/delQos… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.8 CVE-2026-73630 SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/filetree/authFilePublishAccess endpoint, which is registered with C… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-73051 actix-http versions before 3.12.1 contain an HTTP request smuggling vulnerability in the HTTP/1.1 parser that accepts requests with both Content-Leng… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.8 CVE-2026-73049 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getAttributeViewBacklinks endpoint that consults the forbidden a… No fix yet Fix from $4,0002026-08-14 MEDIUM 5.8 CVE-2026-73048 SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getRefIDsByFileAnnotationID endpoint that returns block identifi… No fix yet Fix from $4,0002026-08-14 HIGH 7.7 CVE-2026-72859 Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to obtain S3 … No fix yet Fix from $4,9002026-08-14 MEDIUM 6.5 CVE-2026-72838 FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated use… Patch available Fix from $4,0002026-08-14 HIGH 8.8 CVE-2026-72837 File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers wi… No fix yet Fix from $4,9002026-08-14 HIGH 8.1 CVE-2026-72836 FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Si… Patch available Fix from $4,9002026-08-14 MEDIUM 6.8 CVE-2026-72835 filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-… No fix yet Fix from $4,0002026-08-14 HIGH 8.8 CVE-2026-72833 The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= 1.0.11 contain a privilege escalation vulnerability. A scoped API key minted o… No fix yet Fix from $4,9002026-08-14 MEDIUM 5.4 CVE-2026-72832 Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Co… Patch available Fix from $4,0002026-08-14 HIGH 8.8 CVE-2026-72831 The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API. FlexApiCo… Patch available Fix from $4,9002026-08-14