Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-50735 pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, r… No fix yet Fix from $1,6002026-07-28 HIGH 8.8 CVE-2026-49258 Nebula Mesh is a self-hosted control plane for the Slack Nebula mesh VPN. In versions 0.3.5 and below, the web UI (/ui/*) does not apply the per-oper… Patch available Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-48396 Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. An a… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-48395 Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. An att… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-48394 Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploita… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-48393 Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploita… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-48392 Bridge is affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploita… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-48391 Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the context of the current user. A low-… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 8.2 CVE-2026-48390 Bridge is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerabili… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-48374 Bridge is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary fi… Bridge 15.1.7 / 16.0.6+ Fix from $1,9502026-07-28 MEDIUM 5.5 CVE-2026-47768 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key expos… No fix yet Fix from $1,6002026-07-28 HIGH 7.1 CVE-2026-47726 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, internal/api/audit.go:12 — handleGe… Patch available Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-47725 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DE… No fix yet Fix from $1,6002026-07-28 HIGH 7.8 CVE-2026-18107 A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process inside a container can register an… Patch available Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-16771 In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management … No fix yet Fix from $1,9502026-07-28 CRITICAL 10.0 CVE-2026-16498 The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode … No fix yet Fix from $2,3002026-07-28 HIGH 8.9 CVE-2026-16496 The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow … Mitigation only Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-15992 The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing a… No fix yet Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-15304 The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4.… No fix yet Fix from $1,6002026-07-28 HIGH 8.6 CVE-2026-14869 The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-59933 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through … Patch available Fix from $1,9502026-07-28 HIGH 7.7 CVE-2026-59931 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. In versions 4.0.0 through 5.8.0, 3.3.0 through 3.10.6, 2.2.0 through … Patch available Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-54635 pytonapi is a Python SDK for TONAPI that provides REST API, streaming, and webhook access to the TON blockchain. From 2.0.0 to 2.2.0, TonapiWebhookDi… Patch available Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-48388 Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in t… Photoshop Installer No fix yet Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-48372 Format Plugins is affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current … Format Plugins 2026.07+ Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-48025 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.7, internal/pki/resolver.go:36-64 cons… Patch available Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-67185 TinyWeb through 0.0.8 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by submitting ../ sequenc… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-67184 TinyWeb through 0.0.8 contains a null pointer dereference vulnerability that allows unauthenticated remote attackers to crash worker processes by sen… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-67183 TinyWeb through 0.0.8 contains a memory leak vulnerability that allows unauthenticated attackers to exhaust available memory by sending ordinary well… No fix yet Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-67182 Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to bypass access controls by injecting bare… No fix yet Fix from $1,9502026-07-28