Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-73499 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a user granted READ permissi… Patch available Fix from $4,9002026-08-12 HIGH 7.7 CVE-2026-73498 MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment pa… Patch available Fix from $4,9002026-08-12 HIGH 7.4 CVE-2026-73495 blaze is a Scala library for building asynchronous pipelines, with a focus on network IO. Prior to 0.23.18 and 1.0.0-M42, blaze-server can merge HTTP… Patch available Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-73493 Http4s (http4s-blaze-server) is a minimal, idiomatic Scala interface for HTTP services. Prior to 0.23.18 and 1.0.0-M42, http4s-blaze-server aggregate… Patch available Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-71846 A flaw was found in insights-client. The component's ServiceAccount is bound to a ClusterRole granting cluster-wide secrets get, list, and watch perm… No fix yet Fix from $4,0002026-08-12 HIGH 8.5 CVE-2026-71473 A flaw was found in the `search-v2-operator` component. A user with specific administrative permissions on a managed cluster can exploit a vulnerabil… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-18750 vinny/views.py: (ModifyEmailNotifications) IDOR: view fetches VinceCommEmail by raw pk from URL and toggles email_function/name without checking the … Patch available Fix from $4,0002026-08-12 CRITICAL 9.0 CVE-2026-71471 A flaw was found in acm-search-v2-rhel9. An attacker with administrative privileges on the hub cluster, specifically with patch access to the Search … No fix yet Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-71469 A flaw was found in search-v2-api. An unauthenticated attacker can exploit this by sending requests with unique random bearer tokens. Each unique tok… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-19003 A data source definition containing an over-length file path setting may cause the MongoDB BI Connector ODBC Driver setup dialog to write outside the… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-18749 The type=track branch authorises on _is_my_case(t_attach.case) only and never checks VinceTrackAttachment.shared. A coordinator-uploaded case artefac… Patch available Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-18744 Any authenticated case participant can fetch any OTHER vendor's CaseStatement + per-vul CaseMemberStatus by supplying that member's id — test_func on… Patch available Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18727 A flaw was found in open-iscsi's iscsiuio component. This vulnerability involves an integer underflow and out-of-bounds read during Dynamic Host Conf… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18726 A flaw was found in open-iscsi. This vulnerability allows a remote attacker on the same local network segment to cause a Denial of Service (DoS) in t… No fix yet Fix from $4,0002026-08-12 HIGH 8.2 CVE-2026-17485 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and obtain sensitive information due to an integer underflow. I No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-10534 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to buffer overflow in the IXF IMPORT parser. Db2 after 12.1.5 Fix from $5,7502026-08-12 CRITICAL 10.0 CVE-2024-27253 IBM DOORS Next 7.0.3 through 7.0.3 Interim Fix 018 could allow an authenticated user to bypass security logic to perform unauthorized activities. No fix yet Fix from $5,7502026-08-12 MEDIUM 5.3 CVE-2026-73430 Russh is a Rust SSH client & server library. Prior to 0.62.4, an unauthenticated SSH client can cause a denial of service by sending SSH_MSG_KEX_ECDH… Patch available Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-73429 Russh is a Rust SSH client & server library. Prior to 0.62.4, a malicious SSH server can crash a russh client session with a malformed KEX_ECDH_REPLY… Patch available Fix from $4,0002026-08-12 MEDIUM 5.1 CVE-2026-73423 Astro is a web framework for content-driven websites. From 7.0.0 until 7.0.6, the composable astro/hono pipeline installs security.checkOrigin only t… Patch available Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-73422 Astro is a web framework for content-driven websites. From 2.9.0 until 7.1.0, Astro's server-side View Transition CSS generator interpolates animatio… Patch available Fix from $4,0002026-08-12 MEDIUM 6.8 CVE-2026-73419 NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth.js stores the OAuth/OIDC ant… Patch available Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-73418 NextAuth.js provides authentication for Next.js. Prior to @auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, the exported getToken() helper i… Patch available Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-65370 ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding which could result in request smuggling attacks. This vulnerability is addressed… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-66898 A path traversal vulnerability in LXD allows an attacker to manipulate file system paths during backup import and restore operations. When importing … No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-64826 rConfig before 8.2.13 contains a path traversal vulnerability that allows authenticated attackers to read arbitrary files by supplying unsanitized di… Patch available Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-19654 A unauthenticated remote peer may lead rsyslogd to crash due to a flaw in the optional imptcp module. A crafted input sequence during oversize-frame … No fix yet Fix from $4,9002026-08-12 MEDIUM 5.5 CVE-2026-19502 MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, to a log file on disk. Certain… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.8 CVE-2026-19130 A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific permissions on the hub clust… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-19004 An application using the MongoDB BI Connector ODBC Driver may experience a memory-safety issue when processing output parameters from a stored proced… No fix yet Fix from $4,9002026-08-12