Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-75918 phpMyFAQ before 4.1.7 stores password reset tokens in a publicly accessible tracking file when user tracking is enabled. Unauthenticated attackers ca… No fix yet Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-75917 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (app/src/util/pathName.ts, getL… No fix yet Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-75916 SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup. In genHintItemHTML() (app/src… No fix yet Fix from $4,9002026-08-19 MEDIUM 6.1 CVE-2026-75148 cgltf through 1.15 contains an integer overflow vulnerability in the non-sparse accessor bounds check within cgltf_validate() that allows remote atta… No fix yet Fix from $4,0002026-08-19 MEDIUM 5.1 CVE-2026-75114 Joomla Extension - yootheme.com - Open redirect in CommentController::twitterAuthenticate() in Zoo < 4.1.64 - The referer request parameter is passed… No fix yet Fix from $4,0002026-08-19 CRITICAL 9.3 CVE-2026-74804 Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is inter… No fix yet Fix from $5,7502026-08-19 CRITICAL 10.0 CVE-2026-74803 Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-s… No fix yet Fix from $5,7502026-08-19 MEDIUM 6.5 CVE-2026-70424 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne… No fix yet Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-70423 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privilege… No fix yet Fix from $4,0002026-08-19 HIGH 8.1 CVE-2026-70422 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… No fix yet Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-70421 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Privilege Management vulnerability. A high privileged attacker with remote … No fix yet Fix from $4,9002026-08-19 MEDIUM 5.1 CVE-2026-65612 nnn does not sanitize the filename variable. An attacker can place a file with a crafted name on a shared filesystem, removable media, or inside an e… No fix yet Fix from $4,0002026-08-19 MEDIUM 5.1 CVE-2026-65611 nnn does not sanitize the path variable. An attacker can create a directory on a shared filesystem, removable media, or inside an extracted archive w… No fix yet Fix from $4,0002026-08-19 HIGH 7.1 CVE-2026-56088 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… No fix yet Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-54796 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… No fix yet Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-54795 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injec… No fix yet Fix from $4,9002026-08-19 HIGH 7.2 CVE-2026-54794 Dell OpenManage Enterprise, versions prior to 4.7.0, contains a Server-Side Request Forgery (SSRF) vulnerability. An unauthenticated attacker with re… No fix yet Fix from $4,9002026-08-19 HIGH 7.8 CVE-2026-43961 A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context d… No fix yet Fix from $4,9002026-08-19 CRITICAL 9.8 CVE-2026-16019 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows… No fix yet Fix from $5,7502026-08-19 HIGH 8.8 CVE-2024-58376 Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows att… No fix yet Fix from $4,9002026-08-19 HIGH 7.5 CVE-2020-37267 Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because t… No fix yet Fix from $4,9002026-08-19 HIGH 7.5 CVE-2019-25766 Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scen… No fix yet Fix from $4,9002026-08-19 HIGH 7.5 CVE-2026-76235 A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLan… No fix yet Fix from $4,9002026-08-19 HIGH 7.5 CVE-2026-73394 Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions. No fix yet Fix from $4,9002026-08-19 CRITICAL 9.3 CVE-2026-73391 Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions. No fix yet Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-73390 Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions. No fix yet Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-73389 Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions. No fix yet Fix from $5,7502026-08-19 CRITICAL 9.3 CVE-2026-73388 Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions. No fix yet Fix from $5,7502026-08-19 HIGH 8.1 CVE-2026-73387 Unauthenticated Local File Inclusion in Resido <= 1.5 versions. No fix yet Fix from $4,9002026-08-19 HIGH 7.5 CVE-2026-73386 Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions. No fix yet Fix from $4,9002026-08-19