Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-56161 Improper access control in Azure Logic Apps allows an authorized attacker to disclose information over a network. Azure Logic Apps No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50515 Deserialization of untrusted data in Azure Service Bus allows an authorized attacker to execute code over a network. Azure Service Bus No fix yet Fix from $2,3002026-08-07 CRITICAL 9.9 CVE-2026-50481 Modification of assumed-immutable data (maid) in Azure Active Directory allows an authorized attacker to elevate privileges over a network. Azure Active Directory No fix yet Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-49163 Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elev… Application Insights Profiler No fix yet Fix from $1,9502026-08-07 HIGH 7.8 CVE-2026-8325 A maliciously crafted PDF file, when parsed through Autodesk Revit, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage th… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-7867 A flaw was found in udisks2. A local attacker with an active console session can exploit insufficient authorization checking on the 'as-user' option … No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-7406 A maliciously crafted BMP file, when parsed through certain Autodesk products, can force a Untrusted Pointer Dereference vulnerability. A malicious a… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.5 CVE-2026-7405 A maliciously crafted TIF file, when parsed through certain Autodesk products during image import, can cause an Out-of-Bounds Read in the image handl… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-71554 h2 is a pure-Python implementation of a HTTP/2 protocol stack. Versions up to and including 4.4.0 accept request header blocks containing more than o… Patch available Fix from $1,6002026-08-06 MEDIUM 5.1 CVE-2026-71498 node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.26.1, passing a Buffer whose final bytes form a truncated (incomple… Patch available Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-71488 league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines can cause … Patch available Fix from $1,9502026-08-06 MEDIUM 6.1 CVE-2026-71478 league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 1.5.0 until 2.9.0, the AttributesExtension's href and src unsa… Patch available Fix from $1,6002026-08-06 HIGH 8.7 CVE-2026-71476 Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache ex… Patch available Fix from $1,9502026-08-06 MEDIUM 6.9 CVE-2026-71447 AIL Project contains a stored cross-site scripting vulnerability in the translation controls displayed for chat messages and forum posts. The affect… Patch available Fix from $1,6002026-08-06 MEDIUM 6.9 CVE-2026-71446 AIL Framework contains a stored cross-site scripting vulnerability in the crawler domain view. Crawled URLs were embedded directly into the JavaScrip… Patch available Fix from $1,6002026-08-06 HIGH 8.2 CVE-2026-71445 AIL Framework contained a reflected cross-site scripting vulnerability in the /tag/add_tags endpoint. When an error occurred while processing a tag o… Patch available Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-71439 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.6.0 until 11.16.1, Mermaid Ra… Patch available Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-71437 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 11.5.0 until 11.16.1, Mermaid Ar… Patch available Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-71436 Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. From version 10.6.0 until 10.9.8 and 11.16.1,… Patch available Fix from $1,6002026-08-06 MEDIUM 6.1 CVE-2026-71435 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, the default ("automagic") form notification email … Patch available Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-71434 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.3 and 6.24.2, public frontend forms did not enforce the file upl… Patch available Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-71433 LangGraph Checkpoint Postgres and SQLite Checkpoint are the Postgres and SQLite implementations of LangGraph's checkpoint saver. Prior to 3.1.1, the … Patch available Fix from $1,6002026-08-06 MEDIUM 6.2 CVE-2026-71430 node-re2 provides RE2 regular expression bindings for Node.js. Prior to version 1.25.1, the WrappedRE2::Replace function built its replacement result… No fix yet Fix from $1,6002026-08-06 HIGH 7.6 CVE-2026-71327 Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/… Patch available Fix from $1,9502026-08-06 HIGH 7.0 CVE-2026-71324 Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a … Patch available Fix from $1,9502026-08-06 HIGH 7.0 CVE-2026-70640 llama.cpp builds b1886 through b7445 contain a race condition use-after-free vulnerability in the LLaMA-Android JNI wrapper where bench_1model() and … Patch available Fix from $1,9502026-08-06 MEDIUM 5.5 CVE-2026-70639 llama.cpp builds b1886 through b7445 contain a null pointer dereference vulnerability in the LLaMA-Android JNI wrapper where the bench_1model() funct… Patch available Fix from $1,6002026-08-06 HIGH 7.8 CVE-2026-70638 llama.cpp builds b1886 through b7445 contain an integer overflow vulnerability in the LLaMA-Android JNI wrapper where the new_1batch() function multi… Patch available Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-70636 Flowise through 3.1.4 contains an authentication bypass vulnerability that allows unauthenticated attackers to access the OAuth2 credential refresh e… No fix yet Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-70635 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability that allows authenticated attackers to cause query-… Patch available Fix from $1,9502026-08-06