Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-71847 Ruby JSON is a JSON implementation for Ruby. From 2.20.0 until 2.21.2, Ruby's JSON native C extension clears the consumed JSON::ResumableParser input… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-70561 TestLink 1.9.20 and prior contains an insecure direct object reference vulnerability that allows any authenticated user, including low-privilege gues… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.9 CVE-2026-69127 Kirby is an open-source content management system. Prior to 4.9.5 and from 5.0.0 through 5.5.1, the REST API error handler can return unsanitized PHP… Patch available Fix from $1,6002026-08-07 HIGH 7.3 CVE-2026-48098 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 execute p… No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-48097 NexTor IP Changer is a command-line tool that leverages the Tor network to periodically rotate a user's IP address. Versions prior to 2.0.0 have a co… No fix yet Fix from $1,9502026-08-07 HIGH 7.3 CVE-2026-19231 A security flaw has been discovered in SourceCodester Simple Doctors Appointment System 1.0. This vulnerability affects unknown code of the file /adm… No fix yet Fix from $1,9502026-08-07 HIGH 7.3 CVE-2026-11430 Grav CMS's scheduler-webhook plugin contains an authentication bypass in the webhook token check. When the webhook feature is enabled but no webhookT… Patch available Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2025-71413 Malformed or out-of-sequence frames at the Aviation Very High Frequency Link Control X.25 layers cause repeated resets which may result in increased … No fix yet Fix from $1,6002026-08-07 HIGH 7.1 CVE-2025-71412 Injection of false emergency or status messages over CPDLC may lead to misallocation of resources, operational confusion, and improper response actio… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2025-71411 Broadcast control frames can disconnect multiple aircraft simultaneously leading to delayed clearances and air traffic controller overload. This type… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2025-71410 Unnumbered Disconnect (U DISC) and malformed Aviation Very High Frequency Link Control frames can terminate sessions and lead to a loss of CPDLC func… No fix yet Fix from $1,6002026-08-07 HIGH 7.1 CVE-2025-71409 Lack of authentication for Very High Frequency Data Link messages allows rogue ground stations to inject CPDLC messages leading to unexpected or misl… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2025-63235 In sol commit 373d848 (2024-12-12), the broker does not fully release resources when handling malformed or duplicate CONNECT packets. When clients se… No fix yet Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-66058 Frappe is a full-stack web application framework. Prior to 16.20.0 and 15.112.0, unrestricted access to a Document Follow API (update_follow) is poss… No fix yet Fix from $1,6002026-08-07 HIGH 8.9 CVE-2026-64638 WordPress is vulnerable to a pre-auth reflected XSS vulnerability on the login screen. Via a specially crafted malicious third-party website hoste… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.9 CVE-2026-64637 Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th… No fix yet Fix from $2,3002026-08-07 HIGH 7.7 CVE-2026-64636 An SQL injection vulnerability in Plesk Obsidian up to 18.0.80 for Linux and Windows allows an authenticated user to read arbitrary data from the pan… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-56818 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.136.Final and 4.2.16.Final, the RedisArrayAggregator Redis codec c… Patch available Fix from $1,6002026-08-07 MEDIUM 6.5 CVE-2026-47364 In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing o… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.3 CVE-2026-47363 In versions of the Datadog Android application prior to v541-5.9.2, the exported launcher activity AppActivity accepts an attacker-supplied session (… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.4 CVE-2026-47361 In versions of the Datadog Android application prior to v541-5.9.2, BubbleChatActivity is exported with no permission guard and accepts a SEND intent… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.5 CVE-2026-44965 In versions of the Datadog Android application prior to v545-5.9.2, six App Widget configuration activities (IncidentWidgetActivity, MonitorSavedView… No fix yet Fix from $1,6002026-08-07 MEDIUM 6.5 CVE-2026-44964 In versions of the Datadog Android application prior to v545-5.9.2, OnCallNotificationActivity is declared exported with no permission guard. A co-in… No fix yet Fix from $1,6002026-08-07 MEDIUM 5.3 CVE-2026-19229 A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of … No fix yet Fix from $1,6002026-08-07 HIGH 7.5 CVE-2026-19082 Imager versions from 0.45_02 before 1.034 for Perl may expose adjacent heap bytes via strlen() over-read from zero-count ASCII EXIF entries in copy_s… Patch available Fix from $1,9502026-08-07 MEDIUM 6.3 CVE-2026-71557 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, reference names are not sanitized before be… Patch available Fix from $1,6002026-08-07 HIGH 7.1 CVE-2026-71556 go-git is an extensible git implementation library written in pure Go. Prior to 5.19.2 and 6.0.0-alpha.5, worktree operations (including checkout, st… Patch available Fix from $1,9502026-08-07 HIGH 8.0 CVE-2026-68772 ZenML 0.94.6 contains a remote code execution vulnerability in the CloudpickleMaterializer component that allows attackers with write access to a sha… Patch available Fix from $1,9502026-08-07 HIGH 8.7 CVE-2026-67585 Allocation of Resources Without Limits or Throttling vulnerability in DivvyPayHQ absinthe_federation allows an unauthenticated remote attacker to abo… Patch available Fix from $1,9502026-08-07 MEDIUM 5.3 CVE-2026-66062 SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the content negotiation header par… Patch available Fix from $1,6002026-08-07