Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2026-73488 Flowise versions before 3.1.3 contain an insecure direct object reference vulnerability in the GET /api/v1/organization/customer-default-source endpo… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.0 CVE-2026-73487 Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.0 CVE-2026-73486 Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.0 CVE-2026-73485 Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py… No fix yet Fix from $5,7502026-08-13 HIGH 8.6 CVE-2026-73484 Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_cs… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.4 CVE-2026-73483 Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a… No fix yet Fix from $5,7502026-08-13 MEDIUM 6.6 CVE-2026-45819 baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immed… Patch available Fix from $4,0002026-08-13 MEDIUM 6.0 CVE-2026-18368 In Teltonika Networks RUTOS devices, a vulnerability exists in modbusgwd due to improper handling of Modbus TCP request data. A remote, unauthentic… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.9 CVE-2026-16455 In Teltonika Networks RUTOS devices running versions 7.07.1 through 7.24.1 and TSWOS devices running versions 1.03 through 1.10, a vulnerability exis… No fix yet Fix from $4,0002026-08-13 HIGH 8.8 CVE-2026-12263 Zohocorp ManageEngine Password Manager Pro versions before 13232 and PAM360 versions before 8551 are vulnerable to an authentication bypass vulnerabi… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-59507 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control No fix yet Fix from $5,7502026-08-13 CRITICAL 9.3 CVE-2026-59506 CWE-306: Missing Authentication for Critical Function No fix yet Fix from $5,7502026-08-13 HIGH 8.6 CVE-2026-59505 CWE-284: Improper Access Control No fix yet Fix from $4,9002026-08-13 CRITICAL 9.1 CVE-2026-59504 CWE-602: Client-Side Enforcement of Server-Side Security No fix yet Fix from $5,7502026-08-13 CRITICAL 9.1 CVE-2026-59503 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-359: Exposure of Private Personal Information to an Unauthorized Actor No fix yet Fix from $5,7502026-08-13 MEDIUM 5.3 CVE-2026-59502 CWE-203: Observable Discrepancy No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-59501 CWE-284: Improper Access Control No fix yet Fix from $4,9002026-08-13 CRITICAL 10.0 CVE-2026-59500 CWE-287: Improper Authentication No fix yet Fix from $5,7502026-08-13 HIGH 8.6 CVE-2026-59499 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-19484 @fastify/busboy is a multipart form-data parser. In versions 3.1.0 through 3.2.0, a remote unauthenticated attacker can stall the Node.js event loop … No fix yet Fix from $4,9002026-08-13 MEDIUM 6.6 CVE-2026-19696 Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 to 4.6.7 allows denial of service on Windows No fix yet Fix from $4,0002026-08-13 HIGH 7.5 CVE-2026-19481 @fastify/busboy is a multipart form-data parser. In versions 1.0.0 through 3.2.0, an attacker who can submit multipart form-data can crash the parser… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.9 CVE-2026-16459 Padding oracle attack vulnerability in Oberon microsystem AG’s Oberon PSA Crypto library in all versions since 1.0.0 and prior to 2.1.1 allows an att… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-16458 Padding oracle attack vulnerability in Oberon microsystem AG’s ocrypto library in all versions since 3.0.0 and prior to 4.0.1 allows an attacker to r… No fix yet Fix from $4,0002026-08-13 CRITICAL 10.0 CVE-2026-15413 The Link Factory WordPress plugin is a backdoor. Distributed as a "homepage sentence publisher", it exposes an operator-controlled REST API under /wp… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.4 CVE-2026-14332 The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or nonce verification on one of its… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-14298 Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 fail to properly limit resource consumption when proces… Mattermost Server 10.11.23 / 11.7.8+ Fix from $4,0002026-08-13 MEDIUM 6.4 CVE-2026-3639 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's `ppwp` shortcode attributes in a… No fix yet Fix from $4,0002026-08-13 HIGH 8.8 CVE-2026-11840 Zohocorp ManageEngine Password Manager Pro versions before 13232 and ManageEngine PAM360 versions before 8552 are vulnerable to authenticated SQL inj… No fix yet Fix from $4,9002026-08-13 HIGH 7.2 CVE-2026-18146 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Sc… No fix yet Fix from $4,9002026-08-13