Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.8 CVE-2026-63226 Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.8 CVE-2026-6390 A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-7120 @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolu… Fastify Static 10.1.2+ Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-15074 @fastify/static up to and including version 10.1.0 fails to reject dot-dot path segments in request pathnames before the file-resolution stage. This … Fastify Static 10.1.1+ Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-21723 The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-e… No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-16653 A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of… No fix yet Fix from $1,6002026-07-23 HIGH 7.3 CVE-2026-16632 A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is the function websocket_on_protocol_error in the library lib/facil/http/parsers/w… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.3 CVE-2026-16631 A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component packa… Patch available Fix from $1,6002026-07-23 HIGH 8.8 CVE-2026-61246 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60455 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60439 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java Mitigation only Fix from $1,9502026-07-22 HIGH 8.8 CVE-2026-60373 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 CRITICAL 9.8 CVE-2026-60372 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 8.0 CVE-2026-60371 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 HIGH 7.5 CVE-2026-60370 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 CRITICAL 9.9 CVE-2026-60369 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 HIGH 7.8 CVE-2026-38766 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function No fix yet Fix from $1,9502026-07-22 HIGH 7.8 CVE-2026-38765 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys No fix yet Fix from $1,9502026-07-22 MEDIUM 5.5 CVE-2026-38763 An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828 No fix yet Fix from $1,6002026-07-22 HIGH 8.8 CVE-2026-60368 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $1,9502026-07-22 CRITICAL 9.8 CVE-2026-60367 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 10.0 CVE-2026-60366 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 MEDIUM 5.3 CVE-2026-16630 A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the… No fix yet Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-16629 A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/loc… Patch available Fix from $1,6002026-07-22 MEDIUM 5.3 CVE-2026-16628 A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin En… Patch available Fix from $1,6002026-07-22 HIGH 7.5 CVE-2026-64797 Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring… No fix yet Fix from $1,9502026-07-22 CRITICAL 9.1 CVE-2026-64798 Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-crypto… No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-64796 Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last m… No fix yet Fix from $2,3002026-07-22 MEDIUM 5.4 CVE-2026-64795 Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content… No fix yet Fix from $1,6002026-07-22 MEDIUM 6.5 CVE-2026-64794 Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and condit… No fix yet Fix from $1,6002026-07-22