Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-56846 A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnera… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-56845 An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By includin… No fix yet Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-66326 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 151.0.4129.59+ Fix from $1,9502026-08-04 MEDIUM 6.1 CVE-2026-66325 Server-side request forgery (ssrf) in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 MEDIUM 5.4 CVE-2026-66322 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 CRITICAL 9.6 CVE-2026-66321 Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over… Edge Chromium 151.0.4129.59+ Fix from $2,3002026-08-04 HIGH 8.1 CVE-2026-66318 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network. Edge Chromium 151.0.4129.59+ Fix from $1,9502026-08-04 MEDIUM 5.4 CVE-2026-66317 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a network. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 MEDIUM 5.4 CVE-2026-66316 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-66315 Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network. Edge Chromium 151.0.4129.59+ Fix from $1,9502026-08-04 MEDIUM 5.3 CVE-2026-66314 Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a n… Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 MEDIUM 6.8 CVE-2026-66313 Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 HIGH 8.8 CVE-2026-66312 Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network. Edge Chromium 151.0.4129.59+ Fix from $1,9502026-08-04 MEDIUM 6.2 CVE-2026-66311 Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering locally. Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 HIGH 7.1 CVE-2026-66310 External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information locally. Edge 151.0.4129.59+ Fix from $1,9502026-08-04 MEDIUM 6.1 CVE-2026-65804 Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over… Edge Chromium 151.0.4129.59+ Fix from $1,6002026-08-04 HIGH 7.4 CVE-2026-65802 External control of file name or path in Microsoft Edge for Android allows an unauthorized attacker to disclose information over a network. Edge Chromium 151.0.4129.59+ Fix from $1,9502026-08-04 HIGH 8.8 CVE-2026-62870 Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network. 365 Apps No fix yet Fix from $1,9502026-08-04 CRITICAL 9.8 CVE-2026-18686 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the … No fix yet Fix from $2,3002026-08-04 CRITICAL 9.8 CVE-2026-18685 A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the com… No fix yet Fix from $2,3002026-08-04 MEDIUM 5.6 CVE-2026-11835 Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mo… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-67978 An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame. No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-48399 Adobe Campaign Classic (ACC) is affected by a Violation of Secure Design Principles vulnerability that could result in a Security feature bypass. An … Campaign after 7.4.2 Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-48333 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exp… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-48331 Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitatio… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-48330 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 9.9 CVE-2026-48326 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 10.0 CVE-2026-48323 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result … Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 9.6 CVE-2026-48317 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability t… Campaign after 7.4.2 Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18684 A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the compo… No fix yet Fix from $2,3002026-08-03