Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-70634 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read in the Dictionary compression reverse row iterator (tsl/src/compr… Patch available Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-70633 TimescaleDB through 2.29.1, fixed in commit 517c13e, contains an out-of-bounds read vulnerability in the Gorilla compression reverse row iterator tha… Patch available Fix from $1,6002026-08-06 HIGH 7.8 CVE-2026-70632 FFmpeg versions from 4.4 up to, but not including, 9.0 contain an out-of-bounds heap write vulnerability in the native GoPro CineForm HD (CFHD) decod… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.5 CVE-2026-70631 FFmpeg versions from 0.5 up to, but not including, 9.0 contain an uninitialized heap memory disclosure vulnerability in the native TIFF decoder in li… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.5 CVE-2026-70630 FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native Screenpresso decoder (li… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.5 CVE-2026-70629 FFmpeg versions from 3.0 up to, but not including, 9.0 contain an uninitialized heap memory read vulnerability in the native RSCC decoder (libavcodec… No fix yet Fix from $1,6002026-08-06 HIGH 7.8 CVE-2026-70628 FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signed integer overflow vulnerability in the DVB subtitle parser in libavcodec/dvbsu… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-70559 Dinky's SysConfigController.getAll() handler for GET /api/sysConfig/getAll carries a method-level @SaIgnore annotation that short-circuits the class-… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-70558 Dinky's POST /download/uploadFromRsByLocal handler passes the caller-supplied path parameter directly to new File(path) and file.transferTo(dest) wit… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.5 CVE-2026-70557 diboot-core's POST /common/load-related-data endpoint resolves caller-supplied field names to any @TableField column of any entity and returns those … No fix yet Fix from $1,6002026-08-06 CRITICAL 9.8 CVE-2026-67689 SQL Injection vulnerability in FineAdmin V1.0 allows a remote attacker to execute arbitrary code via the `field` and `order` parameters in paginated … No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-67688 ICS-Park Smart Park Management System v2.0 contains an unrestricted file upload vulnerability in the file upload module. This allows a remote attacke… No fix yet Fix from $2,3002026-08-06 HIGH 8.8 CVE-2026-67687 Insecure Permissions vulnerability in ics-park v.2.0 allows a remote attacker to escalate privileges via the /system/role/save endpoint in RoleContro… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.9 CVE-2026-67622 Flowise through 3.1.4 contains an insecure direct object reference vulnerability in the OpenAI Assistants integration that allows authenticated attac… No fix yet Fix from $2,3002026-08-06 HIGH 7.6 CVE-2026-67621 Flowise through 3.1.4 contains a missing authorization vulnerability that allows authenticated workspace members to perform unauthorized document sto… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-67434 PHP_CodeSniffer tokenizes PHP files and detects violations of a defined set of coding standards. Prior to versions 3.13.6 and 4.0.2, PHP_CodeSniffer … Patch available Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-67422 pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret… Patch available Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-65400 KEV An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 2… macOS 14.8.9 / 15.7.9+ Fix from $2,3002026-08-06 MEDIUM 5.9 CVE-2026-64677 Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, endpoints in Anki's local HTTP server do not adequately constrain requeste… Patch available Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-64665 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, when OAuth login was enabled with a provider that … Patch available Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-64663 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, manipulating user-supplied input incorporated into… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-64662 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.1 and 6.24.0, an authenticated Control Panel user could view con… Patch available Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-64654 GitHub CLI (gh) is GitHub's official command line tool. Prior to version 2.97.0, multiple GitHub CLI commands printed externally controlled gist, API… Patch available Fix from $1,6002026-08-06 MEDIUM 5.1 CVE-2026-64653 GitHub CLI (gh) is GitHub’s official command line tool. Prior to 2.97.0, some HTTP request URLs interpolate variable path components without percent … Patch available Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-63725 sysPass's FileBackupService::doBackupFiles() in lib/SP/Services/Backup/FileBackupService.php around line 388 builds a tar shell command by string-con… No fix yet Fix from $1,9502026-08-06 HIGH 8.6 CVE-2026-63637 Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.go passes regexp filter strin… Patch available Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-62857 Fedify is a TypeScript library for building federated server apps powered by ActivityPub. From version 1.2.0 through the affected 1.9, 1.10, 2.0, 2.1… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-61632 PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. In versions up to and including 10.21.3, the b64 extension is vul… No fix yet Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-5857 Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt/mqtt.c sets topic_len_received=1 before checking topic_len against the 64-byte… Patch available Fix from $1,9502026-08-06 HIGH 7.1 CVE-2026-5856 Contiki-NG's DNS/mDNS resolver skip_name() in os/services/resolv/resolv.c walks DNS wire-format name labels with no packet-boundary check, and the ca… Patch available Fix from $1,9502026-08-06