Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-67191 Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-60113 AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Exte… Ait Dsn 2.2.2+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-60112 AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to o… Ait Gui 2.5.1+ Fix from $2,3002026-07-29 CRITICAL 10.0 CVE-2026-54735 Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in … Prebid Server 4.4.0+ Fix from $2,3002026-07-29 MEDIUM 6.5 CVE-2026-54082 veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an … Patch available Fix from $1,6002026-07-29 MEDIUM 6.9 CVE-2026-54081 veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-par… Patch available Fix from $1,6002026-07-29 MEDIUM 6.9 CVE-2026-54080 veraPDF PDF parser is a PDF parser for veraPDF. Prior to 1.30.2 and 1.31.23, veraPDF-parser contains a denial-of-service vulnerability in veraPDF-par… Patch available Fix from $1,6002026-07-29 HIGH 8.7 CVE-2026-54079 veraPDF validation provides PDF/A and PDF/UA validation, feature reporting, and metadata repair. From 1.17.35 until 1.30.2 and 1.31.71, veraPDF-valid… Patch available Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-54078 veraPDF validation model is an implementation of the veraPDF validation model. From 1.25.73 until 1.30.2 and 1.31.71, veraPDF-validation contains an … Patch available Fix from $1,9502026-07-29 MEDIUM 5.9 CVE-2026-50558 Penelope Shell Handler is a post-exploitation shell handler for authorized security testing. Prior to 0.20.0, the Unix download() implementation in p… Patch available Fix from $1,6002026-07-29 MEDIUM 5.5 CVE-2026-17550 A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can lev… Advance Steel 2026.1.2+ Fix from $1,6002026-07-29 HIGH 7.1 CVE-2026-16543 Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-w… No fix yet Fix from $1,9502026-07-29 HIGH 7.1 CVE-2026-16465 A maliciously crafted DWG or DXF file, when parsed through Autodesk AutoCAD, can force an Out-of-Bounds Read vulnerability. A malicious actor can lev… Advance Steel 2026.1.2+ Fix from $1,9502026-07-29 HIGH 7.8 CVE-2026-16463 A maliciously crafted DXF file, when parsed through Autodesk AutoCAD, can force a Heap-Based Overflow vulnerability. A malicious actor can leverage t… Advance Steel 2026.1.2+ Fix from $1,9502026-07-29 HIGH 7.1 CVE-2026-15228 Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-66724 MWDB Core versions >=2.0.0 and <2.19.0 contain a missing authorization vulnerability in the deprecated config and blob upload endpoints. These endpoi… No fix yet Fix from $1,6002026-07-29 HIGH 7.3 CVE-2026-65947 Joomla Extension - balbooa.com - Various CSRF vectors in the admin interface in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,9502026-07-29 HIGH 7.0 CVE-2026-66723 MWDB Core versions >=2.2.0 and <2.19.0 contain a missing authorization vulnerability in the Remote Instances proxy API. The proxy API does not verify… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-65888 Joomla Extension - balbooa.com - Account takeover vulnerability in Gridbox < 2.20.2 - The socialLogin method allows actors to login as any given user… Gridbox 2.20.2+ Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-65887 Joomla Extension - balbooa.com - Unauthenticated arbitrary password reset in Gridbox < 2.20.2 - The resetPassword method allows actors to reset any u… Gridbox 2.20.2+ Fix from $2,3002026-07-29 HIGH 7.5 CVE-2026-65886 Joomla Extension - balbooa.com - Unauthenticated arbitrary file read in Gridbox < 2.20.2 - The photo viewer allows unauthenticated attackers to view … Gridbox 2.20.2+ Fix from $1,9502026-07-29 HIGH 7.6 CVE-2026-59247 Insufficient Verification of Data Authenticity vulnerability in Gleam allows an adversary in the middle to substitute forged Hex package contents dur… Patch available Fix from $1,9502026-07-29 HIGH 8.3 CVE-2026-54666 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-routes/schema-routes.ts p… Patch available Fix from $1,9502026-07-29 HIGH 8.3 CVE-2026-54664 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schema-parser/base-schema-parser… Patch available Fix from $1,9502026-07-29 MEDIUM 6.1 CVE-2026-54663 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts warmUpR… Patch available Fix from $1,6002026-07-29 HIGH 8.3 CVE-2026-54662 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-gen-process.ts createApiConfi… Patch available Fix from $1,9502026-07-29 HIGH 8.3 CVE-2026-54661 swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templates/base/http-clients/axios-ht… Patch available Fix from $1,9502026-07-29 HIGH 7.4 CVE-2026-54660 swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/resolved-swagger-schema.ts getRemo… Patch available Fix from $1,9502026-07-29 HIGH 8.0 CVE-2026-12703 TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a co… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.4 CVE-2026-9177 A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in vers… No fix yet Fix from $2,3002026-07-29