Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-54719 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.1, the httpserver/updown.go bulkDownload handler for ?… Patch available Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-54659 Pagy is agnostic pagination in plain Ruby. From 43.0.0 until 43.5.6, Pagy::I18n.locale= in gem/lib/pagy/modules/i18n/i18n.rb stored locale values ver… Patch available Fix from $1,6002026-07-28 CRITICAL 9.8 CVE-2026-54658 Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl… Patch available Fix from $2,3002026-07-28 HIGH 8.6 CVE-2026-54650 openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/public_proxy.go forwarded r.URL.P… Patch available Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-54638 gotd/td is a T Telegram MTProto API client in Go. Prior to 0.145.1, proto.UnencryptedMessage.Decode in proto/unencrypted_message.go read attacker con… Patch available Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-47219 find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55415 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.64.0+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55391 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.63.0+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55390 datamodel-code-generator generates Python data models from schema definitions. From 0.59.0 until 0.62.0, XML Schema parsing in src/datamodel_code_gen… Patch available Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-55389 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.62.0+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-54691 datamodel-code-generator generates Python data models from schema definitions. From 0.9.1 until 0.61.0, src/datamodel_code_generator/http.py http.get… Patch available Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-54690 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.61.0+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54656 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.60.2+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54655 datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type values parsed by src/datamodel… Patch available Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54654 datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-template-data comment field is r… Patch available Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-54653 datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf,… Datamodel Code Generator 0.60.2+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-54621 datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union description values in src/datamodel_cod… Patch available Fix from $1,9502026-07-28 CRITICAL 9.4 CVE-2026-6881 A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive … Mitigation only Fix from $2,3002026-07-28 MEDIUM 5.3 CVE-2026-59943 Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, if a malicious actor can supply unrestricted content for rendering by Dompdf … Dompdf 3.1.6+ Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-59942 Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior are vulnerable to a Denial of Service (DoS) attack via resource exhaustion. An at… Dompdf 3.1.6+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-59941 Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior accept a BMP image and generates a PDF-compatible PNG based only on its declared … Dompdf 3.1.6+ Fix from $1,9502026-07-28 MEDIUM 5.3 CVE-2026-56722 Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior, aAn attacker who controls the HTML input can bypass this restriction by embed… Dompdf 3.1.6+ Fix from $1,6002026-07-28 MEDIUM 5.3 CVE-2026-49447 Cosmos provides users the ability self-host a home server by acting as a secure gateway to your application, as well as a server manager. In 0.22.18,… Patch available Fix from $1,6002026-07-28 MEDIUM 5.3 CVE-2026-16581 In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauth… No fix yet Fix from $1,6002026-07-28 HIGH 8.1 CVE-2026-15328 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP request … Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-28 HIGH 8.7 CVE-2026-15325 IBM WebSphere Application Server and IBM WebSphere Application Server - Liberty is vulnerable to HTTP request smuggling due to improper handling of T… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-15280 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 ND Collective Controller is affected by a path-segment injection vulnerability i… Websphere Application Server 26.0.0.9+ Fix from $1,9502026-07-28 HIGH 8.7 CVE-2026-15064 IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to HTTP Response… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-15057 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is vulnerable to a denial of service due to uncontrolled heap allocation. Websphere Application Server 26.0.0.8+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-14996 IBM Aspera Faspex 5 5.0.0 through 5.0.15.4 has addressed a vulnerability related to session management. Aspera Faspex 5.0.16+ Fix from $1,9502026-07-28