Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-13117 An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-12996 A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of serv… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-12945 IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on … Langflow 1.10.2+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-12940 IBM Langflow OSS 1.0.0 through 1.10.1  are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model C… Langflow 1.10.2+ Fix from $2,3002026-07-30 HIGH 8.1 CVE-2026-12932 A memory leak in the tls-crypt-v2 client key extraction in OpenVPN 2.5.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 HIGH 8.4 CVE-2026-11885 IBM PowerVM Hypervisor FW1110.00 through FW1110.20, FW1060.00 through FW1060.71, and FW950.00 through FW950.H1 A carefully crafted OS hypervisor call… No fix yet Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-11771 OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to… Openvpn 2.6.21 / 2.7.5+ Fix from $1,9502026-07-30 MEDIUM 6.2 CVE-2026-67596 CSL 1010 M2M 3G WiFi Module firmware through 2.2.1.4 contains a weak encryption vulnerability that allows unauthenticated attackers to recover all st… No fix yet Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-52680 Apache Kyuubi REST batch multipart upload handling uses the client-supplied multipart filename when creating a temporary uploaded resource. A remote … Kyuubi 1.12.0+ Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-58222 A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When… Mitigation only Fix from $1,9502026-07-30 MEDIUM 5.3 CVE-2026-58216 An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) service. When processing malformed… No fix yet Fix from $1,6002026-07-30 HIGH 8.5 CVE-2026-57862 Kanboard 1.2.52 and prior contains a server-side request forgery vulnerability that allows authenticated users to bypass SSRF protections by supplyin… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-44617 LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constructing LDAP search filters ins… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 MEDIUM 6.5 CVE-2026-44616 LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escaping user-controlled input, al… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2026-44613 Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and a… Zeppelin 0.12.1+ Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-4978 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in UMAI Vision Traffic Analysis System allows SQL … No fix yet Fix from $2,3002026-07-30 MEDIUM 6.5 CVE-2026-48910 A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the markdown renderer, which could … Jspwiki 2.12.4+ Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-28814 Arbitrary Wiki Markup rendering due to lack of authentication in Apache JSPWiki up to 2.12.3 allows attacker to obtain sensitive data stored in JSPWi… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-28813 Apache JSPWiki, up to 2.12.3, is vulnerable to JSON Hijacking, which leads to csrf vulnerabilities. Users are recommended to upgrade to version 2.12.… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-28812 UserManager lack of checks allows impersonation in Apache JSPWiki up to 2.12.3 which may allow attackers to escalate privileges. Users are recommende… Jspwiki 2.12.4+ Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-28811 Debug Messages Revealing Unnecessary Information in Apache JSPWiki up to 2.12.3. Users are recommended to upgrade to version 2.12.4, which fixes this… Jspwiki 2.12.4+ Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-28323 SolarWinds Web Help Desk is found to be affected by a SAML authentication bypass vulnerability. This requires the SAML 2.0 authentication method to b… Web Help Desk 2026.2.1+ Fix from $2,3002026-07-30 MEDIUM 6.5 CVE-2026-23985 A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in … Superset 6.0.0+ Fix from $1,6002026-07-30 MEDIUM 5.3 CVE-2026-23981 An Improper Authorization vulnerability exists in Apache Superset allowing an authenticated user with permissions to update charts to modify dashboar… No fix yet Fix from $1,6002026-07-30 HIGH 8.1 CVE-2026-15658 A vulnerability in the foreUP customer REST API allows any authenticated, low-privilege customer to access an endpoint that returns the records of o… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.5 CVE-2026-15657 A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor merchant credentials in the respons… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-10842 IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 Traditional and Liberty could … Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-6540 Calico's Application Layer Policy (disabled by default), which enforces HTTP rules through Dikastes, fails to perform URL path normalization. As a re… Calico 3.21.7 / 3.22.4+ Fix from $1,9502026-07-30 HIGH 7.5 CVE-2026-67349 OpenCost before 1.121.0 fails to authenticate the GET /helmValues endpoint, exposing base64-decoded HELM_VALUES environment variable containing cloud… Patch available Fix from $1,9502026-07-30 HIGH 8.1 CVE-2026-67348 Julep contains an insecure direct object reference vulnerability in the get_execution_details endpoint that allows authenticated tenants to read anot… No fix yet Fix from $1,9502026-07-30