Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-53503 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor's filters:convolution(<matrix>, <columns>, <should_normalize>… Patch available Fix from $1,9502026-07-31 HIGH 8.7 CVE-2026-53502 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, file_loader decodes percent-encoded path segments after its root-boun… Patch available Fix from $1,9502026-07-31 HIGH 8.2 CVE-2026-53501 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, Thumbor’s HMAC validation can be bypassed due to the use of Python’s … Patch available Fix from $1,9502026-07-31 HIGH 8.2 CVE-2026-53500 Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() … Patch available Fix from $1,9502026-07-31 HIGH 7.3 CVE-2026-18481 Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal sessi… Patch available Fix from $1,9502026-07-31 HIGH 8.7 CVE-2026-55100 hashi-vault-js is a Node.js module for interacting with the HashiCorp Vault API. Prior to 0.5.2, src/Vault.js concatenates unencoded identifier value… Patch available Fix from $1,9502026-07-31 HIGH 7.3 CVE-2026-54737 @phun-ky/defaults-deep is a library like lodash defaultsDeep with array preservation and no lodash dependency. Prior to 2.0.5, defaultsDeep() recursi… Patch available Fix from $1,9502026-07-31 HIGH 8.7 CVE-2026-54729 DSSRF is a Node.js library that provides a wide range of utilities and advanced SSRF defense checks. Prior to 1.0.5, is_url_safe can treat localhost … Patch available Fix from $1,9502026-07-31 CRITICAL 9.6 CVE-2026-54725 vault-secrets-webhook is a Kubernetes mutating webhook that makes direct secret injection into Pods possible. Prior to 1.23.1, parseVaultConfig() in … Patch available Fix from $2,3002026-07-31 MEDIUM 5.4 CVE-2026-34497 Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site… Fms Employee after 2025.3.1 Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-34495 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Sto… Fms Employee after 2025.3.1 Fix from $1,6002026-07-31 MEDIUM 5.5 CVE-2026-34490 Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherw… Xaap 1.53+ Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-21662 Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affec… Fms Employee after 2025.3.1 Fix from $2,3002026-07-31 CRITICAL 9.8 CVE-2026-67822 Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnerability in the /goform/wifiSSIDset endpoint. The function formwrlSSIDset uses sp… No fix yet Fix from $2,3002026-07-31 CRITICAL 9.4 CVE-2026-58048 Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. No fix yet Fix from $2,3002026-07-31 MEDIUM 5.6 CVE-2026-58047 HTTP Smuggling in cPanel allows potential leak of credentials. No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-54707 OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with friends using the Tor network. Pri… Patch available Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-52856 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, a malformed packet received dur… Patch available Fix from $1,9502026-07-31 CRITICAL 9.9 CVE-2026-52855 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.12.3, {{config.}} placeholders in egg… Patch available Fix from $2,3002026-07-31 MEDIUM 5.9 CVE-2026-67607 LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftp… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-59232 Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead per… Patch available Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-59231 Server-Side Request Forgery in the PDF export component in maalfer Pentestify before 1.1.0 allows authenticated users to cause outbound HTTP GET requ… Patch available Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-56568 HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra… Icontrol No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-56571 HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa… Icontrol No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-56570 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse… Icontrol No fix yet Fix from $1,6002026-07-31 MEDIUM 5.1 CVE-2026-56567 HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.5 CVE-2026-52857 Wings is the server control plane for Pterodactyl, a free, open-source game server management panel. Prior to 1.13.0, unbounded json, yaml, and xml c… Patch available Fix from $1,6002026-07-31 HIGH 8.2 CVE-2026-18141 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypa… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.9 CVE-2026-17566 pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command line by interpolating a user-supplied SQL query into a Jinja template and passi… Pgadmin 4 9.18+ Fix from $2,3002026-07-31 CRITICAL 9.0 CVE-2026-17351 The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied query passed to the AI Assistant's execute_sql_query tool to parse, via sqlpar… Pgadmin 4 9.17+ Fix from $2,3002026-07-31