Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-59644 In Bouncy Castle for Java before 1.85, MLS hash-ratchet honours arbitrary 32-bit generation counter from sender. Patch available Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59643 In Bouncy Castle for Java before 1.85, OpenPGP inline-signature policy failures silently ignored. This issue also affects Bouncy Castle for Java FIPS… Patch available Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59642 In Bouncy Castle for Java before 1.85, CMS AuthenticatedData content not bound to MAC when authAttrs present. This issue also affects Bouncy Castle f… Patch available Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59641 In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This issue also affects Bouncy Castle… Patch available Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59640 In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue also affects Bouncy Castle fo… Patch available Fix from $1,9502026-08-03 HIGH 8.7 CVE-2026-59639 In Bouncy Castle for Java before 1.85, CMS verifySignatures returns true for SignedData with zero signers. This issue also affects Bouncy Castle for … Patch available Fix from $1,9502026-08-03 CRITICAL 9.3 CVE-2026-59638 In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in. This issue also affects Bounc… Patch available Fix from $2,3002026-08-03 MEDIUM 5.3 CVE-2026-15055 In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honour unbounded KDF cost from input. This issue also affects Bouncy Castle for Java… Patch available Fix from $1,6002026-08-03 HIGH 7.1 CVE-2026-12185 In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This issue also affects Bouncy Cast… Patch available Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-3245 A deserialization vulnerability in PRISMAproduction Version 6.5 or earlier that may lead to arbitrary code execution. No fix yet Fix from $1,9502026-08-03 HIGH 8.1 CVE-2026-18577 KEV An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 N Central 2026.3+ Fix from $1,9502026-08-02 HIGH 8.6 CVE-2026-10848 The OCPP 1.6 client in subsys/net/lib/ocpp parsed inbound WAMP RPC frames in parse_rpc_msg() (subsys/net/lib/ocpp/ocpp_j.c) using a hand-rolled helpe… Zephyr 4.5.0+ Fix from $1,9502026-08-02 HIGH 7.1 CVE-2026-9856 A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allows an attacker to perform arbitrary file writes via path traversal. The issue r… Patch available Fix from $1,9502026-08-02 MEDIUM 6.5 CVE-2026-10774 Zephyr's Bluetooth Mesh subnet key management leaks one PSA Crypto key slot on every subnet-key teardown. In subsys/bluetooth/mesh/subnet.c, net_keys… Zephyr 4.5.0+ Fix from $1,6002026-08-02 CRITICAL 9.8 CVE-2026-65321 PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper … Patch available Fix from $2,3002026-08-02 MEDIUM 5.4 CVE-2026-68583 luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field that allows lower-privileged us… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-68582 Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-collection endpoint (GET /api/v1… No fix yet Fix from $1,6002026-08-02 HIGH 8.1 CVE-2026-68581 Vikunja versions 0.22.0 through 2.3.0 fail to validate the principal type in API token management. Because user IDs and link-share IDs are independen… Patch available Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-68580 FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL … No fix yet Fix from $1,9502026-08-02 CRITICAL 9.6 CVE-2026-68579 FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer overflow in the Windows clipboard client's CliprdrStream_Read function (client/Windows… Patch available Fix from $2,3002026-08-02 HIGH 7.5 CVE-2026-68578 ArcadeDB versions before 26.7.3 fail to bind the authenticated principal in the MCP HTTP transport, causing all engine permission checks to silently … No fix yet Fix from $1,9502026-08-02 HIGH 7.5 CVE-2026-67357 ArcadeDB versions before 26.7.3 contain an information disclosure vulnerability in the MCP get_server_settings tool that leaks the arcadedb.ha.cluste… No fix yet Fix from $1,9502026-08-02 HIGH 8.8 CVE-2026-67356 ArcadeDB before 26.7.3 binds the real LocalDatabase object into JavaScript trigger contexts with HostAccess.ALL, allowing schema-admins to call getSe… No fix yet Fix from $1,9502026-08-02 MEDIUM 5.9 CVE-2025-71401 better-auth (npm) before 1.4.2 allows an external request to configure baseURL when it is not otherwise defined (e.g., BETTER_AUTH_URL is unset). An … No fix yet Fix from $1,6002026-08-02 HIGH 7.1 CVE-2025-71400 better-auth passkey versions before 1.4.0 contain an insecure direct object reference vulnerability in the passkey deletion endpoint that allows auth… No fix yet Fix from $1,9502026-08-02 HIGH 8.6 CVE-2025-71399 Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalized by removing empty segments,… Patch available Fix from $1,9502026-08-02 MEDIUM 6.4 CVE-2026-12231 The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘ exad_infobox_image’ parameter in all v… No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-18573 A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authorization flows. The issue occurs … Build Of Keycloak No fix yet Fix from $1,6002026-08-02 MEDIUM 6.5 CVE-2026-18572 Keycloak provides authorization services that allow administrators to restrict access to resources based on time policies (for example, only allowing… Build Of Keycloak No fix yet Fix from $1,6002026-08-02 HIGH 7.2 CVE-2026-18571 A flaw was found in the user creation component of Keycloak when Fine-Grained Admin Permissions V2 (FGAP V2) is enabled. This issue allows a sub-admi… Build Of Keycloak No fix yet Fix from $1,9502026-08-02