Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-20708 Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information d… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.8 CVE-2026-20707 Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.8 CVE-2026-20705 Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information dis… No fix yet Fix from $4,0002026-08-11 HIGH 8.9 CVE-2026-20702 Protection mechanism failure for some Intel(R) Data Center Attestation Primitives (Intel(R) DCAP) may allow information disclosure. Unprivileged soft… No fix yet Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-20349 KEV A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall T… Adaptive Security Appliance Software No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-18247 A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentiall… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.8 CVE-2026-12571 An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. No fix yet Fix from $5,7502026-08-11 HIGH 7.0 CVE-2025-8087 A DLL hijacking vulnerability in AMD Power Design Manager could allow a malicious local attacker to escalate privileges during the uninstallation pro… No fix yet Fix from $4,9002026-08-11 HIGH 7.0 CVE-2025-31936 Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an e… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.6 CVE-2025-31356 Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an inform… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.3 CVE-2026-73080 SeaweedFS is a distributed storage system. Prior to 4.24, VolumeServer.FetchAndWriteNeedle in weed/server/volume_grpc_remote.go fetches a caller-supp… Patch available Fix from $5,7502026-08-11 HIGH 8.5 CVE-2026-73079 Sub2API is an AI API gateway platform designed to distribute and manage API quotas from AI product subscriptions. From 0.1.135, to 0.1.168, platform … Patch available Fix from $4,9002026-08-11 HIGH 8.6 CVE-2026-73078 Vim is an open source, command line text editor. Prior to 9.2.0840, runtime/plugin/netrwPlugin.vim loads netrw and runtime/pack/dist/opt/netrw/autolo… Patch available Fix from $4,9002026-08-11 HIGH 8.4 CVE-2026-73077 Vim is an open source, command line text editor. Prior to 9.2.0839, the runtime/ftplugin/sh.vim, runtime/ftplugin/zsh.vim, and runtime/ftplugin/ps1.v… Patch available Fix from $4,9002026-08-11 HIGH 8.4 CVE-2026-73076 Vim is an open source, command line text editor. Prior to 9.2.0847, runtime/autoload/vimball.vim allows a crafted vimball member named .VimballRecord… Patch available Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-73074 Vim is an open source, command line text editor. Prior to 9.2.0841, prop_add_one() in src/textprop.c uses the proplen value from get_text_props() to … Patch available Fix from $4,9002026-08-11 HIGH 8.5 CVE-2026-73072 Vim is an open source, command line text editor. Prior to 9.2.0846, set_sofo() in src/spellfile.c reuses sl_sal_first[] without resetting values left… Patch available Fix from $4,9002026-08-11 MEDIUM 6.8 CVE-2026-73070 Vim is an open source, command line text editor. Prior to 9.2.0842, the socket server backend in src/socketserver.c accepts unbounded client connecti… Patch available Fix from $4,0002026-08-11 CRITICAL 9.1 CVE-2026-73069 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.15.0, Twenty allowed a workspace administrator with the DATA_MOD… Patch available Fix from $5,7502026-08-11 MEDIUM 5.9 CVE-2026-73068 ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.207, th… Patch available Fix from $4,0002026-08-11 MEDIUM 5.9 CVE-2026-6727 A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command inte… No fix yet Fix from $4,0002026-08-11 HIGH 7.9 CVE-2026-6726 An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obt… No fix yet Fix from $4,9002026-08-11 HIGH 8.4 CVE-2026-67180 Google Turbinia allows arbitrary command execution via worker tasks. An attacker with privileges to submit a processing request or influence an evide… Patch available Fix from $4,9002026-08-11 HIGH 7.8 CVE-2026-67179 Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding)… Patch available Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-56721 CamaleonCMS version 2.9.2 and earlier contains a privilege escalation vulnerability via insecure direct object reference (IDOR) that allows authentic… Patch available Fix from $4,9002026-08-11 HIGH 7.1 CVE-2026-53416 Path traversal in Zoom VDI Client and Plugins may allow an authenticated user to conduct information disclosure via local access. No fix yet Fix from $4,9002026-08-11 HIGH 8.3 CVE-2026-53415 Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via … No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-53414 Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of … No fix yet Fix from $4,0002026-08-11 HIGH 8.3 CVE-2026-53413 Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code… No fix yet Fix from $4,9002026-08-11 HIGH 7.6 CVE-2026-48766 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege guest member of a workspace to exfiltrate stored OpenAI-compatible … Patch available Fix from $4,9002026-08-11