Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2026-75625 Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache,… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.0 CVE-2026-75130 Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agent… No fix yet Fix from $5,7502026-08-18 MEDIUM 6.5 CVE-2026-74044 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by s… Patch available Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-74039 Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to … Patch available Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-74038 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrollin… Patch available Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-73502 kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-derefer… Patch available Fix from $4,0002026-08-18 HIGH 7.6 CVE-2026-71880 Interpretation of untrusted input in template engine in GBIF Integrated Publishing Toolkit versions before 3.3.4 allows remote authenticated attacker… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-71879 Missing authentication in initial setup functionality left exposed until first reboot in GBIF Integrated Publishing Toolkit versions before 3.3.4 all… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.2 CVE-2026-71878 Missing authentication in initial setup functionality left exposed after initial setup is completed in GBIF Integrated Publishing Toolkit versions be… No fix yet Fix from $5,7502026-08-18 HIGH 7.8 CVE-2026-71551 Super Productivity is an advanced todo list app with integrated timeboxing and time tracking capabilities. Prior to 18.13.0, the EXEC IPC handler in … Patch available Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-69160 OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in server/handles/sharing.go use st… Patch available Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-68923 MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middleware.csrf.CsrfViewMiddleware on… Patch available Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-68922 MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/views/android/icon_analysis.py u… Patch available Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-67262 Dell PowerStore contains a Missing Authorization vulnerability. An attacker with access to a mapped host could exploit this vulnerability to read fro… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.9 CVE-2026-66780 A flaw was found in the submariner-operator component. The `submariner-k8s-broker-cluster` Role, which is assigned to joined clusters, possesses exce… No fix yet Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-63643 MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, the ADD_CALENDAR handler in defaultmodules/calendar/node_helper.js acc… Patch available Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-63642 MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, checkArticleUrl in defaultmodules/newsfeed/node_helper.js accepts the … Patch available Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-61696 Forem is open source software for building communities. In versions before commit 92eacd16a82cf9007ba8e16a2258b42e3b53ca9c, a malicious value submitt… Patch available Fix from $4,0002026-08-18 MEDIUM 6.9 CVE-2026-54570 AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/… Patch available Fix from $4,0002026-08-18 HIGH 7.9 CVE-2026-54552 sh provides Python process launching. Prior to 2.2.4, the _uid option in sh.py performs an incomplete privilege drop on Linux and Unix-like systems. … Patch available Fix from $4,9002026-08-18 MEDIUM 6.9 CVE-2026-53533 aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior to 5.1.1, SMTP.mail(), SMTP.rcpt(), SMTP.vrfy(), and SMTP.expn() send caller-su… Patch available Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-52609 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-50167 Kurrier is a modern, self-hosted workspace for email, calendar, contacts, and storage. Prior to 1.2.4, Kurrier API endpoints for listing and retrievi… Patch available Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-50161 libre is a generic library for real-time communications with asynchronous input and output support. Prior to 4.8.1, the websock_decode() function in … Patch available Fix from $5,7502026-08-18 HIGH 8.1 CVE-2026-50143 The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify… Patch available Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-49452 WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-hint attribute values into CS… Patch available Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-48508 Lemur manages TLS certificate creation. Prior to 1.9.1, StrictRolePermission and AuthorityCreatorPermission in lemur/auth/permissions.py call flask_p… Patch available Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-44472 Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.63, and 3.23.22, the account activation flow treats email verification as suffic… Patch available Fix from $4,9002026-08-18 HIGH 7.3 CVE-2026-32657 Dell AppSync Version 4.6.0.0, Dell Metro Node Version 8.0.0, Dell UCC Edge Version 3.0.1, Dell VxRail Version 8.0.322, Dell PowerMax Version 10.3.0, … No fix yet Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-75924 A flaw was found in managed-serviceaccount. A compromised addon-manager pod, due to its ClusterRole granting excessive permissions, can read any secr… No fix yet Fix from $4,9002026-08-18