Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-68979 Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer… Nifi 2.11.0+ Fix from $2,3002026-08-03 HIGH 7.2 CVE-2026-67599 ClearOS 7.9 contains an OS command injection vulnerability in the Log Viewer component that allows authenticated attackers to execute arbitrary comma… No fix yet Fix from $1,9502026-08-03 HIGH 7.4 CVE-2026-67598 Emlog Pro through 2.6.23 contains a disabled TLS certificate validation vulnerability in include/service/ai.php that allows network-adjacent attacker… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.1 CVE-2026-66296 Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in lud oaskit allows reflected cross-site scripting via the default H… Oaskit 0.14.1+ Fix from $1,6002026-08-03 HIGH 7.7 CVE-2026-62354 Authorization handling for Parameter Context validation requests in Apache NiFi 1.10.0 through 2.10.0 allows clients with read access to submit propo… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-58139 The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to e… Patch available Fix from $1,6002026-08-03 CRITICAL 9.1 CVE-2026-48031 go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secr… Patch available Fix from $2,3002026-08-03 HIGH 8.4 CVE-2026-47211 Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to constrain behavior. In versio… Patch available Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-18655 Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.amazon-mq-mcp-server) before … No fix yet Fix from $1,6002026-08-03 MEDIUM 6.8 CVE-2026-18654 Key exchange without entity authentication in the EMR SSH helper commands in Amazon AWS CLI before 1.45.28 and AWS CLI v2 before 2.35.3 might allow m… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.4 CVE-2026-18644 A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /system/htmly.php of the compo… No fix yet Fix from $1,6002026-08-03 HIGH 7.3 CVE-2026-18641 A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the fu… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.3 CVE-2026-18632 A security flaw has been discovered in langgenius dify up to 1.14.2. This issue affects the function jinja2.Template of the file api/core/helper/code… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.3 CVE-2026-18631 A vulnerability was identified in jeequan jeepay up to 3.2.9. This vulnerability affects the function WebSecurityConfig of the file jeepay-manager/sr… No fix yet Fix from $1,6002026-08-03 HIGH 7.8 CVE-2026-59913 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain a Missing Authentication for Critical Function vulnerability. A… Display And Peripheral Manager 2.3.0.1005+ Fix from $1,9502026-08-03 HIGH 7.8 CVE-2026-59912 Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3.0.1005, contain an Improper Access Control vulnerability. A low privileged atta… Display And Peripheral Manager 2.3.0.1005+ Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-38447 osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as th… Patch available Fix from $2,3002026-08-03 MEDIUM 6.1 CVE-2026-38446 A stored cross-site scripting (XSS) vulnerability exists in osTicket 1.18.3 due to improper sanitization of the thread entry title field. User-contro… Patch available Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-38444 osTicket v1.18.3 is vulnerable to Stored Cross-Site Scripting (XSS) via the email From-header display name. The value is extracted without sanitizati… Patch available Fix from $1,6002026-08-03 CRITICAL 9.8 CVE-2026-18616 A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18615 A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-b… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18614 A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component… No fix yet Fix from $2,3002026-08-03 MEDIUM 5.9 CVE-2025-15631 A cryptographic weakness exists in affected Omada devices where site credentials are protected using a legacy hashing algorithm that does not provide… Omada Fusion 2.5g Firmware No fix yet Fix from $1,6002026-08-03 MEDIUM 5.9 CVE-2025-15630 A race condition exists in the cloud-based Omada device adoption process when an attacker may be able to interact with the adoption workflow before a… Omada Oc200 V3 Firmware No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2025-15629 A cryptographic weakness exists in the Omada adoption protocol where session encryption keys used to protect communications between controllers and m… Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2025-15628 Affected Omada devices rely on embedded certificates that are shared across deployments to establish trust between controllers and managed devices. … Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2025-15627 A cryptographic weakness exists in the Omada adoption protocol.  The protocol relies on hard-coded cryptographic keys to establish trust and protect … Omada Oc200 V3 Firmware No fix yet Fix from $1,9502026-08-03 MEDIUM 5.9 CVE-2025-15544 A cryptographic weakness exists in the Omada device adoption process.  During adoption, authentication credentials associated with site management ar… Omada Oc200 V3 Firmware No fix yet Fix from $1,6002026-08-03 HIGH 7.2 CVE-2026-61524 WebsiteBaker CMS before 2.13.10 contains an unrestricted file upload vulnerability in the module installation feature that allows authenticated admin… No fix yet Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-61523 WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated administrators to inject arb… No fix yet Fix from $1,9502026-08-03