Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-41921 Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored cross-site scripting vulnerability in the purchase suggestion handler that allows auth… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-18504 fastify is a fast and low overhead web framework for Node.js. Versions of fastify before 5.12.1 are affected by a schema validation bypass when a req… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-16732 fastify is a fast and low overhead web framework for Node.js. Impact: the fix for CVE-2026-3635 added a guard on the forwarded-header reads used to d… No fix yet Fix from $4,0002026-08-18 HIGH 7.3 CVE-2026-15571 A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management soluti… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-12632 Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message type straight off the wire v… Patch available Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-12631 The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/kernel.h) through thread_obj_… Patch available Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-75936 Improper handling of highly compressed data in the GZIP auto-decompression handler in Amazon ion-java before 1.12.0 might allow remote actors to caus… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75935 Uncontrolled memory allocation in the binary Ion stream cursor in Amazon ion-java before 1.12.0 might allow remote actors to cause a denial of servic… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-75877 A flaw has been found in TRENDnet TV-IP751WIC 11.03.03. This vulnerability affects the function SystemNetworkChanged/SystemDDNSChanged/SystemEmailCha… No fix yet Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-75876 A security vulnerability has been detected in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is some unknown functionality of t… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-73529 Plainpad through 1.1.1, fixed in commit d3823fc, contains a missing rate limiting vulnerability that allows unauthenticated attackers to send unbound… Patch available Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-71676 Buffer Overflow vulnerability in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the NAS 5GS decoder chain, triggered when … No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-71675 An issue in Open5GS v.2.7.0 allows a remote attacker to cause a denial of service via the ngap_send_to_nas() function in src/amf/ngap-path.c No fix yet Fix from $4,9002026-08-18 HIGH 7.3 CVE-2026-71417 Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/certificates/upload allowed a non-read-only user to create a duplicate row using … Patch available Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-71317 Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require AuthorityPermission on the parent aut… Patch available Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-71308 Lemur manages TLS certificate creation. From 0.5.0 until 1.9.3, certificate create, upload, and edit requests accepted replaces[] or replacements ide… Patch available Fix from $4,9002026-08-18 HIGH 7.7 CVE-2026-71307 Lemur manages TLS certificate creation. Prior to 1.9.3, GET /api/1/destinations and GET /api/1/destinations/ relied only on authentication while sibl… Patch available Fix from $4,9002026-08-18 HIGH 7.7 CVE-2026-71303 Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_acme_url enforced ACME_DIRECTORY_HOST_ALLOWLIST when an authority was created, but … Patch available Fix from $4,9002026-08-18 HIGH 7.4 CVE-2026-70666 Lemur manages TLS certificate creation. Prior to 1.9.3, an authority-role member could update acme_url through PUT /api/1/authorities/ without revali… Patch available Fix from $4,9002026-08-18 CRITICAL 9.2 CVE-2026-67443 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integ… Patch available Fix from $5,7502026-08-18 MEDIUM 6.9 CVE-2026-67440 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the DEVICE_BROWSE, DEVICE_NODE_ATTRIBUTE, HOST_INTERF… Patch available Fix from $4,0002026-08-18 MEDIUM 6.0 CVE-2026-65985 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the device-webapi-request Socket.IO handler in server… Patch available Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-65984 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, POST /api/refresh in server/api/auth/index.js falls b… Patch available Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-57826 An issue was discovered in openHiTLS 0.2.0 through 0.3.2. In the X.509 certificate chain verification, the basic constraints extension and CA flag pr… Patch available Fix from $5,7502026-08-18 HIGH 7.3 CVE-2026-59915 Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain a Least Privilege Violation vulnerability. A low privileged attacker with … No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-52829 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an unauthenticated IPv4 peer can deterministically terminate a synced Zebra node usin… Patch available Fix from $4,9002026-08-18 MEDIUM 5.9 CVE-2026-52739 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious block producer can terminate zebrad by placing the same shielded transact… Patch available Fix from $4,0002026-08-18 MEDIUM 6.9 CVE-2026-52738 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a consensus-valid block containing a long chain of transparent self-spends to one add… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-52737 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a malicious unauthenticated P2P peer can answer Zebra's outbound getblocks or FindBlo… Patch available Fix from $4,0002026-08-18 HIGH 8.7 CVE-2026-52736 ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a remote unauthenticated P2P peer can stall a Zebra node by racing an invalid block b… Patch available Fix from $4,9002026-08-18