Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-19518 Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipulation. Patch available Fix from $1,6002026-08-11 MEDIUM 6.5 CVE-2026-19517 Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerability in Samsung Open Source rlot… Patch available Fix from $1,6002026-08-11 MEDIUM 6.5 CVE-2026-19391 A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the literal string 'password'. Th… No fix yet Fix from $1,6002026-08-11 HIGH 8.5 CVE-2026-16053 Zohocorp ManageEngine M365 Manager Plus and M365 Security Plus versions below 4820 are affected to Authenticated Path Traversal vulnerability in Exch… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.3 CVE-2026-8158 The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to crash. The issue exclusively … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.1 CVE-2026-6505 The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-6181 The Device Configuration Framework is vulnerable to an authentication bypass flaw. This flaw can only be exploited after authenticating with a viewer… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.7 CVE-2026-5304 An ACAP configuration file lacks input validation, which could potentially lead to privilege escalation. This vulnerability can only be exploited if … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.7 CVE-2026-5303 The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTOU) race condition, which could potentially lead to privilege escalation. This vulner… No fix yet Fix from $1,6002026-08-11 HIGH 7.2 CVE-2026-4757 A VAPIX API parameter had improper input validation which could allow code execution and potentially lead to a privilege escalation. This flaw can on… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-14548 The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of its AJAX actions, allowing an… No fix yet Fix from $1,6002026-08-11 CRITICAL 9.1 CVE-2026-19516 A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-13716 Path traversal in server import and admin file upload in Crafty Controller. Allows a remote, authenticated attacker to upload files to arbitrary path… Crafty Controller 4.10.8+ Fix from $2,3002026-08-11 MEDIUM 5.2 CVE-2026-12052 The USB device-side CDC NCM class control-to-host handler usbd_cdc_ncm_cth in subsys/usb/device_next/class/usbd_cdc_ncm.c builds a fixed-size respons… Patch available Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-11894 The Realtek BEE Bluetooth HCI driver's send callback, bt_hci_bee_send() in drivers/bluetooth/hci/hci_bee.c, violated the bt_hci_driver_api buffer-own… Patch available Fix from $1,6002026-08-11 CRITICAL 9.8 CVE-2026-19425 Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arb… No fix yet Fix from $2,3002026-08-11 MEDIUM 6.4 CVE-2026-16974 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post_meta S… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-11893 The Bluetooth HCI driver for Bouffalo Lab on-chip BLE controllers (BL60x/BL70x/BL61x), bt_bflb_send() in drivers/bluetooth/hci/hci_bflb.c, violates t… Patch available Fix from $1,6002026-08-11 HIGH 8.4 CVE-2026-8917 Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Suite3, and VGAdll: An IOCTL vulnerability allows a local attacker to write a spe… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-24330 A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a malicious archive file from an un… No fix yet Fix from $1,6002026-08-11 HIGH 7.5 CVE-2026-19424 Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a sp… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.3 CVE-2026-66779 Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an authenticated attacker could generate a malicious link… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.3 CVE-2026-66778 SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. An unauthenticated attacker co… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-66777 SAP Approuter does not sufficiently validate certain incoming requests before forwarding them to backend destinations. Due to the complexity of the r… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-66776 SAP Approuter does not consistently enforce integrity verification on certain session-related request headers under specific conditions. An attacker … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.9 CVE-2026-66773 A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which ma… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.1 CVE-2026-66771 SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user … No fix yet Fix from $1,6002026-08-11 MEDIUM 6.3 CVE-2026-66770 Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Languag… No fix yet Fix from $1,6002026-08-11 HIGH 7.9 CVE-2026-66763 SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.4 CVE-2026-66760 SAP Approuter does not correctly validate client certificates in certain callback flows. An attacker with low privileges, holding a certificate from … No fix yet Fix from $1,6002026-08-11