Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-19002 A missing bounds check when parsing stored procedure parameter metadata in the MongoDB BI Connector ODBC Driver can result in an out-of-bounds write … No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-19001 The MongoDB BI Connector ODBC Driver may write outside the bounds of a fixed-size buffer when an application supplies an unusually long catalog, sche… No fix yet Fix from $5,7502026-08-12 MEDIUM 6.5 CVE-2026-18888 The MongoDB BI Connector ODBC Driver converts floating point column values into text without checking that the result fits within the destination buf… No fix yet Fix from $4,0002026-08-12 HIGH 7.1 CVE-2026-16480 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affected by an improper authorization vulnerability in the certain command, allowing a no… Db2 after 12.1.5 Fix from $4,9002026-08-12 MEDIUM 5.5 CVE-2026-18097 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow a local attacker to ob… Db2 after 12.1.5 Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-17616 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access 10.0.9.2 / 11.0.3+ Fix from $5,7502026-08-12 HIGH 7.8 CVE-2026-16695 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of speci… I Access Client Solutions 1.1.9.14+ Fix from $4,9002026-08-12 HIGH 8.5 CVE-2026-16033 A path traversal vulnerability in LXD allows an attacker to achieve arbitrary host file read or unconstrained file creation. When processing image me… No fix yet Fix from $4,9002026-08-12 HIGH 7.1 CVE-2026-14866 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. I Access Client Solutions 1.1.9.14+ Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-13622 A symlink following vulnerability was found in KubeVirt's virt-handler migration proxy. During live migration, virt-handler dials Unix sockets inside… No fix yet Fix from $4,9002026-08-12 HIGH 7.3 CVE-2026-13476 IBM Informix Dynamic Server 14.10, 15.0, and 12.10 could allow an unauthenticated user to execute arbitrary commands with service account privileges … Informix Dynamic Server 15.0.1.13+ Fix from $4,9002026-08-12 CRITICAL 9.6 CVE-2026-13433 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an I… I Access Client Solutions 1.1.9.14+ Fix from $5,7502026-08-12 HIGH 7.8 CVE-2026-13367 IBM Informix Dynamic Server 14.10, and 15.0 contain a local privilege escalation vulnerability in the oninit setuid-root utility. Informix Dynamic Server No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-13105 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. I Access Client Solutions 1.1.9.14+ Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-13094 IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publi… I Access Client Solutions 1.1.9.14+ Fix from $4,9002026-08-12 HIGH 7.5 CVE-2026-11932 IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 thr… Security Verify Access after 11.0.3 Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2026-10543 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to privilege escalation with a specially crafted query. Db2 after 12.1.5 Fix from $5,7502026-08-12 MEDIUM 6.1 CVE-2026-73434 A flaw was found in GStreamer gst-plugins-good (avidemux). In gst_avi_demux_riff_parse_vprp(), the number of available gst_riff_vprp_video_field_desc… Enterprise Linux 1.28.6+ Fix from $4,0002026-08-12 MEDIUM 6.6 CVE-2026-73433 A flaw was found in GStreamer gst-plugins-good (avidemux). When parsing FUJIFILM metadata in an AVI strd chunk, gst_avi_demux_parse_strd() decrements… Enterprise Linux after 1.28.6 Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-73415 jupyterlab is an extensible environment for interactive and reproducible computing, based on the Jupyter Notebook Architecture. Prior to 4.5.10 and 4… Patch available Fix from $4,9002026-08-12 CRITICAL 9.2 CVE-2026-73414 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/win/cmd.js does not escape `(`… Patch available Fix from $5,7502026-08-12 HIGH 8.7 CVE-2026-73413 Shescape is a simple shell escape library for JavaScript. From 2.1.11 until 2.1.14 and 3.0.1, the flag-protection loop in compose in src/internal/com… Patch available Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2026-73412 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, this impacts users of Shescape on Unix systems that explicitly c… Patch available Fix from $4,0002026-08-12 MEDIUM 6.3 CVE-2026-73411 Shescape is a simple shell escape library for JavaScript. Prior to 2.1.14 and 3.0.1, getEscapeFunction in src/internal/unix/dash.js fails to escape ~… Patch available Fix from $4,0002026-08-12 MEDIUM 5.1 CVE-2026-73409 Budibase is an open-source low-code platform. Prior to 3.40.1, packages/server/src/integrations/mongodb.ts passed builder-controlled tlsCertificateKe… Patch available Fix from $4,0002026-08-12 CRITICAL 9.0 CVE-2026-73407 Budibase is an open-source low-code platform. Prior to 3.40.1, RestIntegration._req in packages/server/src/integrations/rest.ts attached credentials … Patch available Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-73406 Budibase is an open-source low-code platform. Prior to 3.39.32, GET /api/global/users/tenant/:id was listed in PUBLIC_ENDPOINTS in packages/worker/sr… Patch available Fix from $4,9002026-08-12 HIGH 8.7 CVE-2026-73332 CamaleonCMS contains a stored cross-site scripting vulnerability in the cama_contact_form plugin that allows low-privileged authenticated attackers t… No fix yet Fix from $4,9002026-08-12 HIGH 7.1 CVE-2026-73331 CamaleonCMS 2.9.1 contains an authenticated SQL injection vulnerability that allows authenticated attackers with post creation or editing privileges … No fix yet Fix from $4,9002026-08-12 MEDIUM 6.6 CVE-2026-73330 CamaleonCMS 2.9.1 contains a server-side template injection vulnerability that allows authenticated administrators to execute arbitrary commands by e… No fix yet Fix from $4,0002026-08-12