Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.6 CVE-2026-54730 authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow with… Patch available Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-52723 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3… Patch available Fix from $5,7502026-08-18 MEDIUM 6.1 CVE-2026-52606 A reflected cross-site scripting (XSS) vulnerability in reportico-web <= 8.1.0 allows remote attackers to execute arbitrary JavaScript in the web bro… No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-50578 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3… Patch available Fix from $4,9002026-08-18 HIGH 7.4 CVE-2026-50577 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3… Patch available Fix from $4,9002026-08-18 MEDIUM 6.8 CVE-2026-50576 ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic patient record. Prior to 1.3… Patch available Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-49228 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product opera… Patch available Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-49225 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revis… Patch available Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-49224 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post revision… Patch available Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-49223 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product revie… Patch available Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-49222 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend product quest… Patch available Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-48744 Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in saleor/permission/utils.py can in… Patch available Fix from $4,0002026-08-18 MEDIUM 6.1 CVE-2026-30250 Cross-site scripting vulnerability in the user documentation field in Beta Systems Software AG ANOW! Automate v.3.3.1.90 allows a remote attacker to … No fix yet Fix from $4,0002026-08-18 HIGH 7.6 CVE-2026-19869 @neo4j/graphql from 5.2.0 until the patched versions fails to enforce field-level @authentication rules on root custom-resolver fields when a type-le… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-18963 A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red… No fix yet Fix from $5,7502026-08-18 HIGH 8.6 CVE-2026-75926 Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, Babel, or TailwindCSS could no… Patch available Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75915 CodeWhale versions before 0.8.64 contain an environment variable exposure vulnerability in the js_execution tool that fails to scrub parent process e… Patch available Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75914 CodeWhale versions before 0.8.64 contain a path traversal vulnerability in the image_analyze tool that fails to canonicalize symlinks before reading … Patch available Fix from $4,9002026-08-18 CRITICAL 9.3 CVE-2026-75913 CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain an argument injection vulnerability in the git_show tool. The model-sup… Patch available Fix from $5,7502026-08-18 HIGH 7.4 CVE-2026-75912 CodeWhale versions before 0.8.64 contain an argument injection vulnerability in the git_blame tool that allows attackers to read arbitrary files by i… Patch available Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-75911 CodeWhale versions before 0.8.64 fail to properly validate the allow_shell configuration parameter from project config files, allowing attackers to e… Patch available Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-75859 CodeWhale versions before 0.8.64 fail to validate file paths in the project config instructions field, allowing attackers to read arbitrary files on … Patch available Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-75858 CodeWhale (packages codewhale / codewhale-tui) versions >= 0.8.41 and < 0.8.64 contain a remote code execution vulnerability in the rlm_eval tool. Th… Patch available Fix from $4,9002026-08-18 HIGH 7.0 CVE-2026-75857 CodeWhale versions >= 0.8.41 and < 0.8.64 contain a vulnerability in the exec_shell_interact (alias exec_interact) tool, whose approval_requirement r… Patch available Fix from $4,9002026-08-18 HIGH 8.6 CVE-2026-75856 CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to prevent time-of-check-time-of-… Patch available Fix from $4,9002026-08-18 MEDIUM 5.5 CVE-2026-75485 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, … No fix yet Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-73834 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed … No fix yet Fix from $4,0002026-08-18 HIGH 8.9 CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not incl… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthori… No fix yet Fix from $4,0002026-08-18 HIGH 8.2 CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows … No fix yet Fix from $4,9002026-08-18