Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-59913 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A… Display And Peripheral Manager 2.3.0.1005+ Fix from $1,9502026-08-03 HIGH 7.8 CVE-2026-59912 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged atta… Display And Peripheral Manager 2.3.0.1005+ Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-38447 osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as th… Patch available Fix from $2,3002026-08-03 MEDIUM 6.1 CVE-2026-38446 A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-contro… Patch available Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-38444 osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitizati… Patch available Fix from $1,6002026-08-03 CRITICAL 9.8 CVE-2026-18616 A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18615 A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-b… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18614 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component… No fix yet Fix from $2,3002026-08-03 MEDIUM 5.9 CVE-2025-15631 A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide… Omada Fusion 2.5g Firmware No fix yet Fix from $1,6002026-08-03 MEDIUM 5.9 CVE-2025-15630 A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a… Omada Oc200 V3 Firmware No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2025-15629 A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and m… Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2025-15628 Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. … Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2025-15627 A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect … Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 MEDIUM 5.9 CVE-2025-15544 A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management ar… Omada Oc200 V3 Firmware No fix yet Fix from $1,6002026-08-03 HIGH 7.2 CVE-2026-61524 WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated admin… No fix yet Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-61523 WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arb… No fix yet Fix from $1,9502026-08-03 HIGH 7.8 CVE-2026-40717 Dell Monitor driver, version 1.0.0.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged atta… Monitor Driver No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-18613 A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the c… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18612 A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the… No fix yet Fix from $2,3002026-08-03 MEDIUM 6.5 CVE-2025-9291 A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certificate identity verification d… Omada Fusion 2.5g Firmware No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-69153 PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19,… Postcss 8.5.23+ Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-69152 The brace-expansion library generates arbitrary strings containing a common prefix and suffix. Prior to 1.1.18, 2.1.4, 3.0.6, and 5.0.9, expand() doe… Brace Expansion 1.1.18 / 2.1.4+ Fix from $1,9502026-08-03 MEDIUM 6.1 CVE-2026-69151 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,… Angular 20.3.27 / 21.2.19+ Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-69149 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,… Angular 20.3.27 / 21.2.19+ Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-68945 Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27,… Angular 20.3.27 / 21.2.19+ Fix from $1,6002026-08-03 MEDIUM 6.5 CVE-2026-68930 Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for recipient channel IDs that were n… Patch available Fix from $1,6002026-08-03 HIGH 8.1 CVE-2026-67611 OpenEMR through 8.2.0 contains an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authent… No fix yet Fix from $1,9502026-08-03 HIGH 8.1 CVE-2026-67610 OpenEMR through 8.2.0 contains an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint that allows unauthenticate… No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-61372 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Jena Fuseki. This issue affects Apache Jena F… Jena Fuseki 6.2.0+ Fix from $1,9502026-08-03 HIGH 8.8 CVE-2026-41453 Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to injec… Patch available Fix from $1,9502026-08-03