Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-73567 sm-crypto provides JavaScript implementations of the Chinese cryptographic algorithms SM2, SM3, and SM4. Prior to 0.5.0, the default no-argument sm2.… Patch available Fix from $5,7502026-08-13 HIGH 7.5 CVE-2026-73566 node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.21, node-tar's filesFilter in src/list.ts uses the recursive mapHas helper t… Patch available Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-73565 @hono/node-server allows running the Hono application on Node.js. From 2.0.0 until 2.0.10, a WebSocket upgrade request to an upgradeWebSocket route w… Patch available Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-73564 frp is a fast reverse proxy. From 0.53.0 until 0.70.1, frp's optional SSH Tunnel Gateway in pkg/ssh/server.go parses an SSH exec channel request by a… Patch available Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-73562 Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.24.1, and 9.7.2, passing a us… Patch available Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-73561 Hub is a Node.js WebSocket server and client with added features. Prior to 0.2.16, every incoming unauthenticated WebSocket connection triggers loadD… Patch available Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-72741 Rainbond through 6.9.7 contains a broken access control vulnerability in the CheckToken function that allows authenticated attackers to access unauth… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.8 CVE-2026-67614 CyberPanel before 3.0.0 contains a hard-coded JWT secret vulnerability in the WebTerminal FastAPI SSH service that allows unauthenticated remote atta… No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-18428 A SQL query validation bypass in the Flint extension query handler in the OpenSearch SQL plugin allows a remote authenticated actor with async query … No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-12236 The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By Type Response received from … Patch available Fix from $4,0002026-08-13 HIGH 7.5 CVE-2024-58374 Hongjing e-HR contains an unauthenticated SQL injection vulnerability in the getSdutyTree servlet endpoint that allows remote unauthenticated attacke… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2019-25765 ASP-CMS contains a SQL injection vulnerability in the commentList.asp endpoint that allows unauthenticated remote attackers to inject arbitrary SQL b… No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-73266 A flaw was found in the clusterclaims-controller component of Multicluster Engine (MCE). An authenticated tenant can exploit this vulnerability by ma… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-59765 SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal Files and Cloud Metadata No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-59109 SQL injection in the Zalktis accounting application via trading-partner-controlled text fields in received electronic invoices. When importing a rece… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-58508 Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation) No fix yet Fix from $5,7502026-08-13 MEDIUM 5.3 CVE-2026-58507 Private Repository Existence Disclosure via go-get Meta Endpoint No fix yet Fix from $4,0002026-08-13 CRITICAL 9.1 CVE-2026-58443 Public-only repository tokens can update private PR head branches No fix yet Fix from $5,7502026-08-13 MEDIUM 6.5 CVE-2026-58442 Repository migration SSRF via multi-answer DNS allow-list bypass No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-58441 SSRF in restore-repo via unsanitized pull_request.yml Head.CloneURL No fix yet Fix from $4,0002026-08-13 MEDIUM 6.8 CVE-2026-58440 Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of private repo content (incomplet… No fix yet Fix from $4,0002026-08-13 HIGH 8.1 CVE-2026-58439 Branch Protection Bypass via PR Retargeting Preserves Stale `official` Approval Flag No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58438 Cross-repository IDOR in issue-dependency removal lets an attacker tamper with and comment on private repos they cannot access No fix yet Fix from $4,9002026-08-13 HIGH 7.1 CVE-2026-58437 Repository Visibility Manipulation via Git Push Options No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-58436 ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests No fix yet Fix from $4,9002026-08-13 MEDIUM 5.4 CVE-2026-58435 Gitea LFS Deploy-Key Privilege Escalation No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-58434 Private Repository Metadata Remains Accessible After Access Revocation No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-58433 Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting No fix yet Fix from $5,7502026-08-13 MEDIUM 5.9 CVE-2026-58432 Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-58428 Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939) No fix yet Fix from $4,0002026-08-13