Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-16796 Improper neutralization of argument delimiters in the install_packages() method in AWS Bedrock AgentCore Python SDK before 1.18.1 might allow a remot… No fix yet Fix from $1,9502026-07-23 HIGH 8.2 CVE-2026-16002 The affected product is vulnerable to an Out-of-bounds read, which may allow an attacker to crash the parsing process and cause a denial of service. No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-15981 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is … No fix yet Fix from $2,3002026-07-23 MEDIUM 5.4 CVE-2026-15968 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Progress MOVEit Transfer. This issue affects M… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $1,6002026-07-23 CRITICAL 9.9 CVE-2026-15630 A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15967 Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15966 Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-10697 Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 HIGH 7.8 CVE-2026-65706 FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_swaprect video filter that allows attackers to corrupt heap … Ffmpeg after 8.1.2 Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-65705 FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulnerability in the vf_floodfill video filter that allows attackers to corrupt heap… Ffmpeg after 8.1.2 Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-64785 SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters reach an HTTP/1.1 backend thro… No fix yet Fix from $1,6002026-07-23 HIGH 7.8 CVE-2026-65704 FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability that allows attackers to cause heap corruption by supplying a crafted ffconcat fil… Ffmpeg after 8.1.2 Fix from $1,9502026-07-23 HIGH 7.8 CVE-2026-65703 FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulnerability in the TDSC video decoder that allows remote attackers to cause heap c… Ffmpeg after 8.1.2 Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-63359 The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-cra… Mitigation only Fix from $2,3002026-07-23 HIGH 7.8 CVE-2026-60122 gpsd through release-3.27.5, fixed at commit 4c06658, contains a code injection vulnerability in the gpsprof utility that allows an attacker who cont… Patch available Fix from $1,9502026-07-23 HIGH 8.7 CVE-2026-47722 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, `internal/configgen/generator.go:86… Patch available Fix from $1,9502026-07-23 CRITICAL 9.4 CVE-2026-47670 DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-47669 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`… No fix yet Fix from $2,3002026-07-23 HIGH 7.5 CVE-2026-25800 Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC transport protocol. Starting in version 0.1.0 and prior to version 0.11.15, th… Patch available Fix from $1,9502026-07-23 HIGH 8.8 CVE-2026-15212 The WPO365 | Login plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 43.2. This is due to the Ajax_S… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-12353 An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly sending HTTP requests to the TL… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.6 CVE-2026-65010 Datasets through 5.00, fixed in commit ad2d853, contains a symlink-following vulnerability in Extractor.extract() that allows local attackers to writ… Patch available Fix from $1,6002026-07-23 HIGH 8.2 CVE-2026-63765 Chatwoot before 4.16.0 contains an authentication bypass vulnerability in the direct uploads controller that allows unauthenticated attackers to crea… Patch available Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-16756 Missing connection and header-read timeouts and the absence of a concurrent-connection cap in the default serve() path of Amazon aws-smithy-http-serv… No fix yet Fix from $1,9502026-07-23 CRITICAL 10.0 CVE-2026-6516 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. No fix yet Fix from $2,3002026-07-23 HIGH 7.5 CVE-2026-65919 Meshery before 1.0.57 contains an unauthenticated arbitrary file read vulnerability in the /api/system/fileView and /api/system/fileDownload endpoint… Patch available Fix from $1,9502026-07-23 HIGH 7.1 CVE-2026-65918 PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains an out-of-bounds heap read vulnerability in the GIF decoder's read_from_tensor … Torchvision after 0.28.0 Fix from $1,9502026-07-23 MEDIUM 5.1 CVE-2026-65763 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Maps 5.0.0-6.0.4 - Improper validation of user inputs lead to a reflective XSS vul… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.1 CVE-2026-65762 Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Guestbook 5.0.0-6.1.0 - Improper validation of user inputs lead to a reflective XS… No fix yet Fix from $1,6002026-07-23 HIGH 8.6 CVE-2026-65702 Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration that allows unauthenticated re… No fix yet Fix from $1,9502026-07-23