Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.4 CVE-2026-50236 An authenticated SSRF flaw was found in the OpenShift Console Dev Console webhook helpers. User-supplied target URLs are fetched server-side without … No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-13739 A legacy endpoint in Command Center contained an unauthenticated server-side request forgery (SSRF) vulnerability related to the handling of arbitrar… No fix yet Fix from $1,9502026-08-11 CRITICAL 9.2 CVE-2026-13738 CommServe contained an authorization bypass vulnerability affecting a limited set of command execution operations. Software customers upgrade to res… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.2 CVE-2026-13737 CommServe contained an allowlist bypass vulnerability affecting command execution authorization. Software customers upgrade to resolved maintenance … No fix yet Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain function… No fix yet Fix from $2,3002026-08-11 MEDIUM 5.3 CVE-2026-73162 Affected versions of MISP cti-transmute expose several state-changing account operations as GET requests: * /account/follow * /account/d… Patch available Fix from $1,6002026-08-11 MEDIUM 6.0 CVE-2026-33922 A path traversal vulnerability was discovered in the Offline archives functionality of the local web interface due to insufficient validation of an i… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.2 CVE-2026-33921 The Windows installer deployed Npcap leaving its access restriction option at the insecure default value, so the driver was accessible to every local… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.1 CVE-2026-73161 Affected versions of cti-transmute improperly handle conversion-table values passed through the search highlighting feature. The highlight() function… Patch available Fix from $1,6002026-08-11 HIGH 8.7 CVE-2026-73160 Affected versions of cti-transmute contain an SSRF vulnerability in the /fetch_misp_event and /misp_search_events endpoints. The URL validation rou… Patch available Fix from $1,9502026-08-11 MEDIUM 5.1 CVE-2026-73159 Affected versions of cti-transmute allow a tag's icon value to be stored and later interpolated into HTML through Vue's v-html. The helper mapIcon() … Patch available Fix from $1,6002026-08-11 MEDIUM 5.1 CVE-2026-73158 Affected versions of cti-transmute insufficiently validate saved graph configuration data. Graph configurations can contain style properties that are… Patch available Fix from $1,6002026-08-11 HIGH 7.1 CVE-2026-72694 A flaw was found in MRTG. When the MRTG daemon is started as a root user and subsequently drops privileges, a local, low-privileged attacker can expl… No fix yet Fix from $1,9502026-08-11 HIGH 7.8 CVE-2026-72693 `openvt -u` is intended to identify the owner of the current VT and then execute `login` as that user from a privileged context. In the documented `k… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.3 CVE-2026-71218 A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function, which accepts a peer-control… Patch available Fix from $1,6002026-08-11 HIGH 7.5 CVE-2026-71217 A flaw was found in iperf3. A remote attacker can exploit this vulnerability by sending crafted control-channel JSON with oversized numeric parameter… Patch available Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-15567 A flaw was found in Wildfly. A remote unauthenticated attacker can trigger OutOfMemoryError as CSIv2Util's GSS token decoder reads an attacker-contro… No fix yet Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-15565 A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on any @ServerEndpoint class th… No fix yet Fix from $1,9502026-08-11 HIGH 7.4 CVE-2026-15563 A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI l… No fix yet Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-15562 A flaw was found in EAP's jboss-remoting. A remote unauthenticated attacker who can reach :8080 (or :9990, or :4447) and complete an Upgrade: jboss-r… No fix yet Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-15561 A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. missing limits on size and count would allow an attacker to use an unauthentica… No fix yet Fix from $1,9502026-08-11 HIGH 8.1 CVE-2026-15560 when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an… No fix yet Fix from $1,9502026-08-11 HIGH 8.1 CVE-2026-15556 A flaw was found in Picketlink's SP signature validation; a SAML response containing zero assertion elements matching the signature check can allow a… No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-15555 A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River u… No fix yet Fix from $1,9502026-08-11 HIGH 7.4 CVE-2026-15554 the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attributes without requiring any shared-secret authentication. This enables an unaut… No fix yet Fix from $1,9502026-08-11 CRITICAL 9.8 CVE-2026-10579 A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, pe… No fix yet Fix from $2,3002026-08-11 MEDIUM 5.3 CVE-2026-73156 Affected versions of cti-transmute fail to HTML-escape attacker-controlled values used in ECharts Sunburst and Treemap tooltip formatters. Slice name… Patch available Fix from $1,6002026-08-11 MEDIUM 5.3 CVE-2026-73155 Affected versions of cti-transmute allow authenticated users to add or remove emoji reactions on comments without first checking whether those users … Patch available Fix from $1,6002026-08-11 MEDIUM 5.3 CVE-2026-73140 Affected versions of cti-transmute fail to apply comment-level access-control rules when generating evaluation report exports. Although normal commen… Patch available Fix from $1,6002026-08-11 HIGH 7.3 CVE-2026-19418 The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2020-11069) became ineffective in TYPO3 v13.0, where TYPO3 CMS started serving t… Patch available Fix from $1,9502026-08-11