Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.0 CVE-2026-49500 Dell Alienware Command Center (AWCC), versions prior to 6.14.20.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerab… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-47721 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, POST /api/scheduler and DELETE /api/scheduler in server/api… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-47720 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the TDengine DAQ storage connector's escapeTdString functio… Patch available Fix from $4,0002026-08-18 HIGH 8.2 CVE-2026-47719 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Prior to 1.3.2, the DEVICE_WEBAPI_REQUEST and DEVICE_PROPERTY Socket.IO han… Patch available Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-19671 Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompressed-byte limits when extractin… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-19670 Malcolm's nginx Lua role-based access control (RBAC) layer decides whether an authenticated user may reach a role-restricted path (e.g. /htadmin, /au… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.4 CVE-2026-12520 The Sierra Wireless HL7800 cellular modem driver (drivers/modem/vendor_standalone/hl7800.c, located at drivers/modem/hl7800.c in v4.4.0 and earlier) … Patch available Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-70667 Lemur manages TLS certificate creation. Prior to 1.9.3, _validate_revocation_url in lemur/certificates/verify.py checked the original CRL or OCSP URL… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-65959 Vitess is a database clustering system for horizontal scaling of MySQL. In 24.0.2 and earlier, the /debug/vrlog endpoint registered by addHttpEndpoin… Patch available Fix from $4,0002026-08-18 CRITICAL 9.9 CVE-2026-55166 Lemur manages TLS certificate creation. Prior to 1.9.2, authenticated users could influence an ACME authority acme_url without an effective server-si… Patch available Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-55163 Lemur manages TLS certificate creation. Prior to 1.9.2, PUT /api/1/roles/ in lemur/roles/views.py:298 authorized updates with RoleMemberPermission(ro… Patch available Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-55162 Lemur manages TLS certificate creation. Prior to 1.9.2, lemur/certificates/verify.py accepted CRL Distribution Point and OCSP responder URLs from upl… Patch available Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-47630 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit migh… No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-47629 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause improper input validation. A successful exploit might… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-47628 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an allocation of resources without limits. A successf… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-47627 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A successful exploit might lead to de… No fix yet Fix from $5,7502026-08-18 MEDIUM 6.5 CVE-2026-47606 NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit migh… No fix yet Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-24185 NVIDIA NVOS for network switches contains a vulnerability in the secure shell (SSH) server configuration component while PKA-only mode is enabled, wh… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-24184 NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an a… No fix yet Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-24183 NVIDIA Cumulus Linux contains a vulnerability in the user management component, where an unprivileged user could use improper privilege management on… No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-17106 The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, Untar/UntarUncompressed, and the ApplyLayer helpers) do not confine filesystem o… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.7 CVE-2025-9211 Unescaped stored values in application security page in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers … No fix yet Fix from $4,0002026-08-18 HIGH 8.1 CVE-2025-9210 Missing signature validation in JSON Web Tokens in Otalio Ship Property Management System versions before 2.22.0 allows authenticated attackers to es… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2021-43718 An Authentication Bypass vulnerability exists in EPSON EH-TW5350 EPSON 150075647YWWV110, which could let a remote malicious user cause a Denial of Se… Fix unknown Fix from $4,0002026-08-18 CRITICAL 9.0 CVE-2026-75625 Kraken agents fail to verify peer-to-peer downloaded blobs against their requested SHA-256 digest before committing to the content-addressable cache,… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.0 CVE-2026-75130 Context7 through 2.1.2 contains a prompt injection vulnerability that allows attackers to execute malicious instructions in connected AI coding agent… No fix yet Fix from $5,7502026-08-18 MEDIUM 6.5 CVE-2026-74044 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbitrary directory contents by s… Patch available Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-74039 Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers with allow_run_as enabled to … Patch available Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-74038 Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows unauthenticated remote attackers to cause denial of service by enrollin… Patch available Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-73502 kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 until 0.144.0, openapi3filter.ValidateRequest can encounter a NULL-pointer-derefer… Patch available Fix from $4,0002026-08-18