Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-7327 An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 all… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-7326 A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures a… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.9 CVE-2026-70606 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0,… No fix yet Fix from $1,6002026-08-05 MEDIUM 5.9 CVE-2026-70605 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 7.4 CVE-2026-70604 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0,… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.0 CVE-2026-70603 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.6 CVE-2026-70602 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-70601 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-b… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.9 CVE-2026-70599 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-b… Patch available Fix from $1,6002026-08-05 MEDIUM 6.3 CVE-2026-70597 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b… Patch available Fix from $1,6002026-08-05 CRITICAL 9.1 CVE-2026-60053 Insufficient Session Expiration vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Administrative API keys remained u… Answer 2.0.2+ Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-60023 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Deleted… Answer 2.0.2+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-50749 Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authenticated user can reject arbitrary… Answer 2.0.2+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-48912 Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing ownership check in the avatar… Answer 2.0.2+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-48911 Insufficient Verification of Data Authenticity vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing authoriza… Answer 2.0.2+ Fix from $1,9502026-08-05 MEDIUM 6.1 CVE-2026-53992 ProjectSend r2029 contains a reflected cross-site scripting vulnerability in thumbnails-regenerate.php that allows remote attackers to inject arbitra… Patch available Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-49331 A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy forwards client-supplied identit… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-48834 Improper Handling of Length Parameter Inconsistency vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Unauthenticate… Answer 2.0.2+ Fix from $1,9502026-08-05 MEDIUM 6.8 CVE-2026-39924 Flarum before 1.8.16 contains an improper session invalidation vulnerability that allows attackers who hold a valid session token to retain full acco… Patch available Fix from $1,6002026-08-05 HIGH 8.1 CVE-2026-39923 Flarum before 1.8.16 contains a password reset token expiry bypass vulnerability that allows unauthenticated attackers to reuse expired password rese… Patch available Fix from $1,9502026-08-05 MEDIUM 5.3 CVE-2026-18531 IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use of a weak HMAC session signin… Maximo Application Suite 9.0.28 / 9.1.20+ Fix from $1,6002026-08-05 CRITICAL 9.8 CVE-2026-16442 A flaw was found in the SAML broker component of Keycloak, which is used to manage identity federation and user authentication. The issue occurs beca… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $2,3002026-08-05 CRITICAL 9.4 CVE-2026-15587 Improper Privilege Management in Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Cloud Platform allows an authenticated attacker to… Mitigation only Fix from $2,3002026-08-05 HIGH 8.8 CVE-2026-15572 A flaw was found in Keycloak's Dynamic Client Registration (DCR) security policy management. The "Allowed Protocol Mapper Types" policy, which restri… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-13477 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privileged user to execute arbitrary c… Qradar Security Information And Event Manager Mitigation only Fix from $1,9502026-08-05 MEDIUM 5.3 CVE-2026-12762 IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensitive information exposed in man… Business Automation Insights No fix yet Fix from $1,6002026-08-05 CRITICAL 9.8 CVE-2026-10025 IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 has an XML External Entity (XXE) injection vulnerability. The vulne… Qradar Security Information And Event Manager No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-54876 Issue summary: A malicious TLS server can cause a memory leak in a TLS client that has enabled OCSP response checking by sending an OCSP response tha… Patch available Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-17613 Penpot’s ::import-binfile RPC command lacks authorization on the optional file-id parameter, allowing any authenticated user to overwrite any files o… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-16102 A flaw was found in the Dynamic Client Registration (DCR) component of Keycloak, an identity and access management solution. The default DCR policy f… Build Of Keycloak 26.4.14 / 26.6.5+ Fix from $1,9502026-08-05