Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-73532 Fluent Forms Pro 6.2.7 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned updat… No fix yet Fix from $5,7502026-08-13 HIGH 8.1 CVE-2026-73515 PostGIS before 3.7.0beta2 contains an out-of-bounds read vulnerability that allows attackers to cause memory disclosure or a server crash by supplyin… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-73514 The address_standardizer extension for PostGIS through 3.7.0, fixed in commit 423570b, contains an out-of-bounds write vulnerability that allows a da… Patch available Fix from $4,9002026-08-13 MEDIUM 6.9 CVE-2026-55401 CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an … No fix yet Fix from $4,0002026-08-13 MEDIUM 6.0 CVE-2026-55400 CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.1 CVE-2026-19744 Cross-site Scripting in the Markdown renderer in maalfer Pentestify before 2.3.2 allows authenticated users to execute arbitrary JavaScript in the ap… Patch available Fix from $4,0002026-08-13 HIGH 7.3 CVE-2026-19710 A vulnerability was found in SourceCodester Simple Student Information System. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-19487 Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expression match results when a stale failure flag ends the Aho-Corasick prescan ear… Patch available Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73558 vLLM is an inference and serving engine for large language models. Prior to 0.27.0, an integer overflow in blockIdx.x * 2 * d in activation_kernels.c… Patch available Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-73557 vLLM is an inference and serving engine for large language models. From 0.20.2rc0 until 0.26.0, safe_load_prompt_embeds in vllm/renderers/embed_utils… Patch available Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73556 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_outp… Patch available Fix from $4,0002026-08-13 MEDIUM 5.3 CVE-2026-73555 vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the validation_exception_handler in vllm/entrypoints/openai/serve… Patch available Fix from $4,0002026-08-13 HIGH 7.6 CVE-2026-73509 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the authenticated /api/fs/batch_rename handler in server/handles/fsbatch… Patch available Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-73508 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.dns.AbstractDns… Patch available Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-73507 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.xml.XmlFrameDec… Patch available Fix from $4,9002026-08-13 MEDIUM 6.1 CVE-2026-73506 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, write(s rune) in src/terminal/writer.go e… Patch available Fix from $4,0002026-08-13 HIGH 7.8 CVE-2026-73505 Oh My Posh is the most customisable and low-latency cross platform/shell prompt renderer. Prior to 29.35.1, the setStyle() function in src/segments/p… Patch available Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70464 rsync daemon 2.0.0 before 3.5.0 contains a denial of service vulnerability that allows unauthenticated remote attackers to exhaust daemon connection … No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-70463 rsync 3.1.0 before 3.5.0 contains an authorization bypass in auth users directive parsing. The auth users parser uses comma-only tokenization when sp… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-70462 rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows attackers to permanently disa… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-70461 rsync 3.2.5 before 3.5.0 contains a heap out-of-bounds write vulnerability that allows remote unauthenticated attackers to write one attacker-control… No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-70460 rsync 2.3.3 before 3.5.0 contains a path traversal vulnerability that allows a malicious sender to escape the module root by exploiting symlinks with… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-70459 rsync 3.0.0 before 3.5.0 contains a null pointer dereference vulnerability in the daemon child process that allows remote attackers to crash the daem… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-70458 rsync 3.0.0 before 3.5.0 contains an out-of-bounds write vulnerability that allows attackers to corrupt memory by triggering HLINK_BUMP processing on… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.5 CVE-2026-70457 rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is used directly as an index into a… No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-70456 rsync 3.0.1 before 3.5.0 contains an out-of-bounds write vulnerability in the read_args() function that allows a malicious sender to corrupt adjacent… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70455 rsync 3.4.2 before 3.5.0 contains a denial of service vulnerability that allows a remote sender to exhaust system resources by specifying the --zt sh… No fix yet Fix from $4,9002026-08-13 HIGH 8.0 CVE-2026-70454 rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on… No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-70453 rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a denial of … No fix yet Fix from $4,9002026-08-13 HIGH 7.4 CVE-2026-70452 rsync 3.1.0 before 3.5.0 contains an access control bypass vulnerability that allows remote attackers to circumvent hosts deny rules by inducing DNS … No fix yet Fix from $4,9002026-08-13