Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-72910 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.22.0, the merge_account, pause_job_for_doc, trigger_job… Patch available Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-72909 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.112.0 and 16.23.0, the ReceivablePayableReport prepare_conditions pa… Patch available Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-72908 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template function in erpnext/accounts… Patch available Fix from $1,6002026-08-10 MEDIUM 6.5 CVE-2026-72907 ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function in erpnext/accounts/utils.py … Patch available Fix from $1,6002026-08-10 CRITICAL 9.3 CVE-2026-72904 Firecrawl turns entire websites into LLM-ready markdown or structured data. Prior to 2.11.32, a critical arbitrary file read vulnerability exists in … Patch available Fix from $2,3002026-08-10 HIGH 8.1 CVE-2026-72903 Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.235, a malicious SFTP server can return a backslash traversal file… Patch available Fix from $1,9502026-08-10 MEDIUM 5.4 CVE-2026-72743 SQLBot through 1.10.0, fixed in commit c3f40a5, contains a stored cross-site scripting vulnerability in the SQText dashboard component that renders T… Patch available Fix from $1,6002026-08-10 HIGH 7.8 CVE-2026-63622 A flaw was found in libvirt. A local attacker, specifically a process running as the confined `swtpm` user, could exploit a symlink-following vulnera… No fix yet Fix from $1,9502026-08-10 CRITICAL 9.3 CVE-2026-48160 react-tracked provides state usage tracking with Proxies. Between 2026-05-18 19:26:36 and 2026-05-19 15:22:45, the default branch contained malicious… No fix yet Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-18982 A flaw was found in the RHOAI training-operator. This vulnerability allows a user with standard edit or admin roles in any Kubernetes namespace to es… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18951 A flaw was found in the Red Hat OpenShift AI (RHOAI) overlay for the training operator. The RHOAI overlay incorrectly aggregates `trainjobs` manageme… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18950 A flaw was found in odh-dashboard. An authenticated user of the dashboard can exploit a vulnerability related to how RoleBindings are created. The sy… No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18949 A flaw was found in odh-dashboard. This vulnerability allows an attacker, who has compromised the dashboard's Service Account (SA) token, to exploit … No fix yet Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-18948 A flaw was found in Feast. The system improperly deserializes user-defined functions (UDFs) stored in its registry, which are serialized using the 'd… No fix yet Fix from $2,3002026-08-10 HIGH 8.5 CVE-2026-18947 A flaw was found in Feast. An authorization bypass vulnerability exists in the /materialize and /materialize-incremental endpoints. By sending a spec… No fix yet Fix from $1,9502026-08-10 MEDIUM 5.5 CVE-2026-18942 A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by … No fix yet Fix from $1,6002026-08-10 HIGH 7.7 CVE-2026-18941 A flaw was found in Feast and feast-operator. The default configuration for both the Feast SDK and the feast-operator is "no_auth," meaning no securi… No fix yet Fix from $1,9502026-08-10 HIGH 7.6 CVE-2026-18621 A flaw was found in Data Science Pipelines (DSP). An attacker with namespace editor privileges can bypass security hardening by submitting a maliciou… No fix yet Fix from $1,9502026-08-10 HIGH 7.1 CVE-2026-18620 A flaw was found in Data Science Pipelines. A restricted user, or tenant, can exploit an improper authorization vulnerability in the setDefaultServic… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-18618 A flaw was found in ml-metadata. The statically-linked gRPC stack in ml-metadata is outdated, making it vulnerable to known HTTP/2 denial of service … No fix yet Fix from $1,9502026-08-10 HIGH 8.8 CVE-2026-18617 A flaw was found in the Data Science Pipelines Operator (DSPO). A namespace editor can exploit a vulnerability in the spec.database.customExtraParams… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-18611 A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such … No fix yet Fix from $1,9502026-08-10 HIGH 8.7 CVE-2026-18608 A flaw was found in the Data Science Pipelines Operator (DSPO). The operator's ClusterRole, which defines its permissions, includes extensive privile… No fix yet Fix from $1,9502026-08-10 MEDIUM 6.5 CVE-2026-16456 A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can exploit a vulnerability in the … No fix yet Fix from $1,6002026-08-10 HIGH 8.0 CVE-2026-15581 A flaw was found in the TrustyAI Service (TAS) deployment. This vulnerability allows any pod on the cluster network to bypass authentication and dire… No fix yet Fix from $1,9502026-08-10 HIGH 8.1 CVE-2026-15467 A flaw was found in the trustyai-service-operator's LMEvalJob controller. An authenticated user within the cluster can exploit this vulnerability by … No fix yet Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-14450 A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP head… No fix yet Fix from $2,3002026-08-10 HIGH 8.8 CVE-2026-13717 A flaw was found in the Red Hat OpenShift AI (RHOAI) MaaS Gateway. Improper configuration of the Gateway in a model-serving context allows a standard… No fix yet Fix from $1,9502026-08-10 HIGH 7.5 CVE-2026-11810 The UpdateHub firmware-update agent's probe handler (z_impl_updatehub_probe() in subsys/mgmt/updatehub/updatehub.c) parses the JSON metadata returned… Patch available Fix from $1,9502026-08-10 CRITICAL 9.9 CVE-2026-72902 Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, Dokploy allows an authenticated user to execute arbitrary commands o… Patch available Fix from $2,3002026-08-10