Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-18667 A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sens… No fix yet Fix from $2,3002026-08-03 HIGH 8.7 CVE-2026-69249 python-cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, when resolving invali… Patch available Fix from $1,9502026-08-03 MEDIUM 6.9 CVE-2026-69248 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. Prior to 49.0.0, if an intermediate constrain… Patch available Fix from $1,6002026-08-03 HIGH 8.2 CVE-2026-69247 cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 44.0.0 until 50.0.0, pkcs7_decrypt_der, … Patch available Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67975 Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67974 A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to caus… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67970 Incorrect access control in the DS_SetDestPathCmd() component of NASA cFS v7.0.1 allows attackers to access sensitive components via a path traversal. No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67969 An issue in the HS_MonitorApplications() component of NASA cFS v7.0.1 allows attackers to force the processor to reset via supplying a crafted HS.App… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67977 An integer overflow in the Svc::FileDownlink::SendPartial component of fprime framework v4.2.2 allows attackers to cause a Denial of Service (DoS) vi… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67973 An issue in the CFDP receive path of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via replaying final CFDP PDUs. No fix yet Fix from $1,9502026-08-03 MEDIUM 6.3 CVE-2026-48115 Misskey is an open source, federated social media platform. All Misskey servers running versions 2024.5.0 and later, but prior to 2026.5.4, contain a… No fix yet Fix from $1,6002026-08-03 HIGH 8.9 CVE-2026-47746 Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, are vulnerable to timing attacks durin… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.1 CVE-2026-46714 Misskey is an open source, federated social media platform. IVersions 8.63.0 and later, but prior to 2026.5.4, contain a vulnerability that can cause… No fix yet Fix from $1,6002026-08-03 CRITICAL 9.2 CVE-2026-46713 Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD… Mitigation only Fix from $2,3002026-08-03 HIGH 7.5 CVE-2026-10849 The hawkBit device management client in subsys/mgmt/hawkbit accumulates the body of an HTTP response from the update server into a heap buffer in res… Zephyr 4.5.0+ Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-69246 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supplies the Host header sep… Patch available Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-69245 Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of a cookie Domain that cookie u… Patch available Fix from $1,6002026-08-03 HIGH 7.1 CVE-2026-69244 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.3, an out-of-bounds heap read could occur in the C resp… Patch available Fix from $1,9502026-08-03 MEDIUM 6.3 CVE-2026-69243 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the HTTP parsers were vulnerable to a request smuggl… Patch available Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-67972 An issue in the CF_CFDP_RecvMd() component of NASA cFS v7.0.1 allows attackers to contrl where received content and data is stored, possibly leading … No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-67976 The Ref::SignalGen component of fprime framework v4.2.2 does not validate the safety of user-controlled parameters, allowing attackers to cause a Den… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-69240 Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function define… Patch available Fix from $2,3002026-08-03 HIGH 8.4 CVE-2026-66065 Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. Versions … No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-52102 An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as ro… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-51775 SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-51190 The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL e… No fix yet Fix from $2,3002026-08-03 HIGH 8.1 CVE-2026-52521 A SQL injection vulnerability in Z-BlogPHP 1.7.5 allows authenticated attackers to execute arbitrary SQL commands via the id parameter in the Comment… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.4 CVE-2026-52520 Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/article.php). A remote authen… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-49132 OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to inject arbitrary HTML or JavaScrip… Patch available Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-49131 OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with firewall rule management privile… Patch available Fix from $1,6002026-08-03