Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-65432 Apache CXF reads a top-level WSDL through its hardened StaxUtils path, which disables XML DTDs and external entities. However, any <wsdl:import> or <… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-64958 An incomplete fix for CVE-2026-50645 means that it is still possible to perform a denial of service attack on Apache CXF by sending a message with ma… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-57819 Apache CXF allows to set a limit on the number of form parameters in a JAX-RS message via the "maxFormParameterCount" configuration option. However, … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 8.1 CVE-2026-57817 The OpenID Connect Core 1.0 specification mandates that the RP MUST validate the `c_hash` parameter when operating in the Hybrid Flow. If an Apache C… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-54225 Apache CXF allows to control the maximum attachment size via the "attachment-max-size". Prior to Apache CXF 4.2.3 and 4.1.8 and 3.6.12, there was no … Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-19034 A vulnerability was determined in Shibby Tomato 1.28.0000. Affected by this vulnerability is the function new_qoslimit_stop of the file /tmp/qoslimit… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.5 CVE-2026-55980 A denial-of-service vulnerability in CatchPulse could allow an attacker to conduct a stack buffer overrun attack, leading to a denial-of-service cond… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.2 CVE-2026-55979 An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is l… No fix yet Fix from $1,6002026-08-06 HIGH 8.4 CVE-2026-55978 An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter co… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-64640 Apache Polaris did not consistently validate storage locations supplied during table and view registration. An authenticated principal with permissi… Polaris after 1.6.0 Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19022 A vulnerability was determined in OpenHands up to 0.62.0. The affected element is the function initialize_repo of the file OpenHands/resolver/send_pu… No fix yet Fix from $1,6002026-08-06 HIGH 7.8 CVE-2026-64601 In the Linux kernel, the following vulnerability has been resolved: ALSA: us144mkii: capture_urb_complete: redundant usb_anchor_urb corrupts anchor … No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-64599 In the Linux kernel, the following vulnerability has been resolved: crypto: amlogic - avoid double cleanup in meson_crypto_probe() When meson_alloc… No fix yet Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-64598 In the Linux kernel, the following vulnerability has been resolved: smb/client: Fix error code in smb2_aead_req_alloc() The "*num_sgs" variable is … No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-64597 In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_close() replay A response-bearing attempt … No fix yet Fix from $2,3002026-08-06 HIGH 7.8 CVE-2026-64588 In the Linux kernel, the following vulnerability has been resolved: fuse-uring: fix data races on ring->ready On weakly-ordered architectures, the … No fix yet Fix from $1,9502026-08-06 HIGH 7.0 CVE-2026-64587 In the Linux kernel, the following vulnerability has been resolved: net: ethernet: arc: emac: quiesce interrupts before requesting IRQ Normal RX/TX… No fix yet Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-64586 In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: drain bus_reset work on device removal brcmf_fw_crashed() and t… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-64585 In the Linux kernel, the following vulnerability has been resolved: can: esd_usb: kill anchored URBs before freeing netdevs esd_usb_disconnect() fr… No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-64584 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_midi: cancel pending IN work before freeing the midi object The … No fix yet Fix from $1,9502026-08-06 HIGH 7.8 CVE-2026-64583 In the Linux kernel, the following vulnerability has been resolved: usb: gadget: udc: bdc: free IRQ and drain func_wake_notify before teardown The … No fix yet Fix from $1,9502026-08-06 CRITICAL 10.0 CVE-2026-5430 The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker t… Api Control Plane 4.1.0.257 / 4.2.0.197+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-1728 Tokens issued to a low-privileged user are not sufficiently restricted, allowing them to be used to access product-level Admin REST APIs. Exploitati… Api Control Plane 4.0.0.384 / 4.1.0.248+ Fix from $2,3002026-08-06 HIGH 7.3 CVE-2026-19021 A security vulnerability has been detected in SourceCodester Computer Repair Shop Management System 1.0. Affected by this issue is some unknown funct… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19020 A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-19011 A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packages/server/src/routes/agents.… No fix yet Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-19010 A security vulnerability has been detected in TinyAGI 0.0.20. Impacted is the function processMessage of the file packages/main/src/index.ts of the c… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-19009 A weakness has been identified in TinyAGI 0.0.20. This issue affects the function collectFiles of the file packages/core/src/response.ts of the compo… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19008 A vulnerability was identified in mf-yang openclaw-cn up to 0.2.1. This issue affects the function assertNoSymlinkEscape of the file src/agents/sandb… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.0 CVE-2026-18915 Invocation of process using visible sensitive information vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute eta-otp-lock allow… No fix yet Fix from $1,6002026-08-06