Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-73244 kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/sr… Patch available Fix from $4,0002026-08-11 MEDIUM 5.8 CVE-2026-73243 kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView i… Patch available Fix from $4,0002026-08-11 HIGH 8.3 CVE-2026-73242 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptM… Patch available Fix from $4,9002026-08-11 HIGH 8.3 CVE-2026-73241 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.30.0, FreeRDP server-side RDSTLS in libfreerdp/core/rdstls.c accepts an a… Patch available Fix from $4,9002026-08-11 MEDIUM 6.1 CVE-2026-73235 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the Xerces SAX2 XMLReader constructed in src/Base/Reader.cpp b… Patch available Fix from $4,0002026-08-11 HIGH 7.8 CVE-2026-73234 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, PropertyFileIncluded::Restore() in src/App/PropertyFile.cpp co… Patch available Fix from $4,9002026-08-11 HIGH 8.5 CVE-2026-73233 FreeCAD is a free and open-source multiplatform 3D parametric modeler. Prior to 1.1.2, the FEM Displacement Constraint task dialog in src/Mod/Fem/Gui… Patch available Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-73232 ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a malicious target server to cause an out-of-memory denial of service because th… Patch available Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-73231 Faker generates massive amounts of fake data in the browser and Node.js. Prior to 10.5.0, the faker.helpers.fake method in src/modules/helpers/eval.t… Patch available Fix from $4,9002026-08-11 MEDIUM 5.9 CVE-2026-73230 Ente provides end-to-end encrypted cloud services and security tools. Prior to 2026.07.28, Ente 2of3 card format version 1 stored the secret byte len… Patch available Fix from $4,0002026-08-11 CRITICAL 9.8 CVE-2026-73034 DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s… Patch available Fix from $5,7502026-08-11 CRITICAL 9.6 CVE-2026-73032 PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou… Patch available Fix from $5,7502026-08-11 HIGH 8.7 CVE-2026-73031 telegram-search contains a stored cross-site scripting vulnerability that allows remote attackers to execute arbitrary JavaScript in victims' browser… Patch available Fix from $4,9002026-08-11 MEDIUM 6.3 CVE-2026-71845 A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bear… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.0 CVE-2026-71475 A flaw was found in insights-client. A compromised managed cluster, referred to as a 'spoke', can inject unencoded data into the Insights API URL pat… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.3 CVE-2026-71474 A flaw was found in insights-client. When the application receives a non-200 response, it logs the request headers, which can include the cloud.opens… No fix yet Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-71468 A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly reuses a user's bearer token … No fix yet Fix from $4,0002026-08-11 HIGH 7.5 CVE-2026-71467 A flaw was found in search-v2-api. The authentication middleware in the affected component unconditionally skips authentication when a request includ… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.4 CVE-2026-70339 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium 151.0.4129.78+ Fix from $4,0002026-08-11 MEDIUM 6.1 CVE-2026-66146 Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in GMS 9.5.1 (Build 9510.1044) and earlier versions that allow a remote attacker … No fix yet Fix from $4,0002026-08-11 CRITICAL 9.1 CVE-2026-66145 An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke… No fix yet Fix from $5,7502026-08-11 HIGH 8.7 CVE-2026-48813 Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralizati… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-48804 python-socketio is a Python implementation of the Socket.IO realtime client and server. The python-socketio server stores binary `EVENT` and `ACK` me… Patch available Fix from $4,9002026-08-11 CRITICAL 10.0 CVE-2026-45618 LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa… No fix yet Fix from $5,7502026-08-11 HIGH 8.1 CVE-2026-19091 The GeoDirectory – WP Business Directory Plugin and Classified Listings Directory plugin for WordPress is vulnerable to arbitrary file deletion due t… Patch available Fix from $4,9002026-08-11 HIGH 8.1 CVE-2026-18844 The firmware of the Pulsetto Vagus Nerve Stimulator accepts several undisclosed commands over its Bluetooth Low Energy (BLE) interface. These command… No fix yet Fix from $4,9002026-08-11 CRITICAL 9.8 CVE-2026-16230 The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-13457 The InstaWP Connect – 1-click WP Staging & Migration plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.3 CVE-2024-14042 A vulnerability was found in Open5GS up to 2.7.1. This affects the function hss_ogs_diam_s6a_air_cb/hss_ogs_diam_s6a_ulr_cb of the file src/hss/hss-s… Patch available Fix from $4,0002026-08-11 MEDIUM 5.3 CVE-2026-73228 Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing in rest_framework/request.py … Patch available Fix from $4,0002026-08-11