Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-68587 SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and get… No fix yet Fix from $1,9502026-08-03 HIGH 8.6 CVE-2026-68586 SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints (/api/ref/getBacklinkDoc and… No fix yet Fix from $1,9502026-08-03 MEDIUM 5.8 CVE-2026-68585 SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that returns document root metadata… No fix yet Fix from $1,6002026-08-03 HIGH 8.6 CVE-2026-68584 SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning endpoints getHeadingChildrenDOM,… No fix yet Fix from $1,9502026-08-03 HIGH 7.2 CVE-2026-67608 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an OS command injection vulnerability in action_au… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-64827 Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.… No fix yet Fix from $2,3002026-08-03 HIGH 7.8 CVE-2026-18642 Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. Thi… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-18601 A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon… No fix yet Fix from $2,3002026-08-03 HIGH 8.8 CVE-2026-18600 A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. This affects the function network.switch_info/network.switch_status of the file /usr… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-18108 Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte… Net\ 0.86+ Fix from $2,3002026-08-03 HIGH 8.1 CVE-2026-18092 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass via XML signature wrapping because new_from_xml reads assertion identity wi… Net\ 0.86+ Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-18089 Net::SAML2 versions before 0.86 for Perl allow SAML authentication bypass by verifying responses against the response-embedded certificate in verify_… Net\ 0.86+ Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-56609 HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TL… Icontrol No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-56608 HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users t… Icontrol No fix yet Fix from $1,6002026-08-03 CRITICAL 9.8 CVE-2026-2346 Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affe… No fix yet Fix from $2,3002026-08-03 HIGH 8.0 CVE-2026-18599 A flaw has been found in GL.iNet GL-MT3000 up to 4.4.5. The impacted element is the function logread.set_config of the file /usr/lib/oui-httpd/rpc/lo… No fix yet Fix from $1,9502026-08-03 HIGH 8.8 CVE-2026-18598 A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function logread.get_system_log of the file /usr/lib/oui-h… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.3 CVE-2026-18574 An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an una… No fix yet Fix from $2,3002026-08-03 HIGH 8.8 CVE-2026-69082 CTI-Transmute contained a cross-site request forgery vulnerability in the administrative user deletion functionality. The /account/delete/<id> endpoi… Patch available Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-69079 CTI-Transmute contains an uncontrolled resource-consumption vulnerability in the unauthenticated /activity_timeline endpoint. The endpoint accepts a … Patch available Fix from $1,9502026-08-03 HIGH 8.8 CVE-2026-69078 CTI-Transmute is affected by a server-side request forgery vulnerability in the evaluation report PDF-generation functionality. User-controlled CTI … Patch available Fix from $1,9502026-08-03 MEDIUM 5.5 CVE-2026-68742 A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining p… Openshift Container Platform No fix yet Fix from $1,6002026-08-03 CRITICAL 10.0 CVE-2026-33591 A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially … No fix yet Fix from $2,3002026-08-03 HIGH 7.3 CVE-2026-0392 eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.9 CVE-2026-69075 FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted … Patch available Fix from $1,6002026-08-03 MEDIUM 6.5 CVE-2026-63563 Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initi… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-62416 Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accep… No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-60011 Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected … No fix yet Fix from $1,6002026-08-03 MEDIUM 6.9 CVE-2026-8794 PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnera… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.9 CVE-2026-8793 PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploi… No fix yet Fix from $1,6002026-08-03