Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-54609 QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handleReconnectRequest forwards REC… No fix yet Fix from $1,9502026-07-28 HIGH 7.2 CVE-2026-54605 OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, providing clients and servers. From 0.5.5 to 1.1.5, OAuth::Consumer#token_request parse… Patch available Fix from $1,9502026-07-28 HIGH 8.6 CVE-2026-54603 OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0 to 2.0.21, a protocol-relati… Patch available Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-54345 gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the Diameter AVP decoder computes an AVP data length by subtra… Gopacket 1.6.1+ Fix from $1,9502026-07-28 HIGH 7.5 CVE-2026-54332 gopacket provides packet processing capabilities for Go. In version 1.6.0 and earlier, the sFlow ExtendedGatewayFlow decoder in layers/sflow.go reads… Gopacket 1.6.1+ Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-51275 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 APIC frame parsing function in audiolib allows remote attackers to ex… No fix yet Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-51274 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in the ID3v2 SYLT synchronized lyrics parser in audiolib allows remote attackers t… Mitigation only Fix from $1,9502026-07-28 HIGH 7.8 CVE-2026-51273 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the ID3 tag parsing function showID3Tag() of the embedded … No fix yet Fix from $1,9502026-07-28 MEDIUM 6.9 CVE-2026-18085 An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Po… Unified Endpoint Manager No fix yet Fix from $1,6002026-07-28 MEDIUM 6.1 CVE-2026-18084 Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Sc… Unified Endpoint Manager No fix yet Fix from $1,6002026-07-28 HIGH 7.6 CVE-2026-16313 A flaw was found in sg3_utils. The sg_inq command, when invoked with the --export option, outputs device identification data without sanitizing contr… Patch available Fix from $1,9502026-07-28 MEDIUM 6.5 CVE-2026-7868 IBM OPENBMC FW1110.00 through FW1110.20, and FW1060.00 through FW1060.71 allows ReadOnly users to escalate privileges and give themselves administrat… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.5 CVE-2026-7775 IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.6, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.0.0 t… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.4 CVE-2026-67181 Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize HTTP message boundaries by… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.9 CVE-2026-66754 Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerability in the Request::remove_prefix function that allows remote unauthenticated at… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.4 CVE-2026-66752 tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize request framing by sending a … No fix yet Fix from $1,6002026-07-28 MEDIUM 5.4 CVE-2026-66751 Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to archive any room on the server … No fix yet Fix from $1,6002026-07-28 MEDIUM 6.5 CVE-2026-66749 Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulnerability that allows authenticated attackers to crash the server by supplying a valid… No fix yet Fix from $1,6002026-07-28 HIGH 8.8 CVE-2026-66748 Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated remote code execution vulnerability that allows users with custom_fields manage p… Patch available Fix from $1,9502026-07-28 MEDIUM 5.4 CVE-2026-66746 Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arbitrary response headers by em… No fix yet Fix from $1,6002026-07-28 MEDIUM 5.4 CVE-2026-62828 Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a network. Edge No fix yet Fix from $1,6002026-07-28 HIGH 7.5 CVE-2026-61609 Pterodactyl is a free, open-source game server management panel. From 1.7.0 until 1.13.0, the authentication rate limiter defined in RouteServiceProv… Patch available Fix from $1,9502026-07-28 HIGH 8.1 CVE-2026-54593 Pterodactyl is a free, open-source game server management panel. Prior to Panel version 1.12.3 and Wings version 1.12.2, the Wings /upload/file endpo… Patch available Fix from $1,9502026-07-28 HIGH 7.1 CVE-2026-54545 wakaru is a JavaScript decompiler and unminifier toolkit. From 1.0.0 until 1.4.0, @wakaru/cli sanitizes bundle-controlled module filenames only once … Patch available Fix from $1,9502026-07-28 HIGH 8.8 CVE-2026-51270 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the htmlToUTF8() HTML entity decoding function. The function pars… Mitigation only Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-51268 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untr… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.6 CVE-2026-51271 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The fun… No fix yet Fix from $2,3002026-07-28 HIGH 8.8 CVE-2026-51269 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the connecttospeech() function. The application accepts attacker-… No fix yet Fix from $1,9502026-07-28 CRITICAL 9.8 CVE-2026-51267 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application s… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51266 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynam… No fix yet Fix from $2,3002026-07-28