Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-66340 The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login a… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-66098 The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootload… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.6 CVE-2026-5917 libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-29036 cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within c… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-19560 Use after free in Blink in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted H… Chrome 151.0.7922.137+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-19559 Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HT… Chrome 151.0.7922.137+ Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-19558 Use after free in Extensions in Google Chrome prior to 151.0.7922.137 allowed an attacker who convinced a user to install a malicious extension to ex… Chrome 151.0.7922.137+ Fix from $4,9002026-08-11 HIGH 8.3 CVE-2026-19557 Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922.137 allowed a remote attacker who had compromised the renderer process to pote… Chrome 151.0.7922.137+ Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-19556 Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML… Chrome 151.0.7922.137+ Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-18710 A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to applica… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.1 CVE-2026-71290 Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe… Httpclient 5.6.4+ Fix from $5,7502026-08-11 MEDIUM 6.5 CVE-2026-66832 When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query s… No fix yet Fix from $4,0002026-08-11 HIGH 8.3 CVE-2026-66154 An insufficient certificate validation in a privileged communication workflow, was identified in a GMS application 9.5.1 (Build 9510.1044) and earlie… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-66150 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi… No fix yet Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-66149 Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker wi… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.3 CVE-2026-66148 An authenticated command injection vulnerability was identified in GMS Command-Line Interface (CLI) 9.5.1 (Build 9510.1044) and earlier versions whic… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.4 CVE-2026-66147 An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote… No fix yet Fix from $5,7502026-08-11 HIGH 7.1 CVE-2026-63177 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, role-based access control enforced in the Nginx OpenResty Lua layer evalu… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-63134 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` protects file extraction with libarchive's secure flags… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-63133 Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives with no limit on entry count… No fix yet Fix from $4,0002026-08-11 HIGH 8.8 CVE-2026-55676 Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` a… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.9 CVE-2026-48765 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from… Patch available Fix from $5,7502026-08-11 HIGH 8.2 CVE-2026-48763 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a deprecated public upload endpoint at `GET /api/v1/typebots/{typebotId}/blocks/{b… Patch available Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-48762 TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI "Create Transcription" action handler fetches a user-supplied audio URL using … Patch available Fix from $4,0002026-08-11 HIGH 8.2 CVE-2026-19550 A flaw was found in FreeIPA. The trust-fetch-domains command is gated by a read-only permission on the trust object rather than a trust-administratio… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-29035 CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that allows unauthenticated remot… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.4 CVE-2026-19579 Snipe-IT before 8.6.0 contains an authorization bypass (insecure direct object reference) in the asset checkout-request cancellation endpoint. The ca… Snipe It 8.6.0+ Fix from $4,0002026-08-11 HIGH 8.4 CVE-2026-18634 An insecure handling of serialized objects vulnerability was found in the one of the service of GMS application 9.5.1 (Build 9510.1044) and earlier v… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-15606 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.29.9. This is due… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-14863 FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote cod… No fix yet Fix from $4,9002026-08-11