Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-74999 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS. Patch available Fix from $4,0002026-08-17 HIGH 7.2 CVE-2026-74998 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses from the CSS (Cascading Style Sheets) proxy were not validated, which may result… Patch available Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-74997 In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_learn driver of the markasjunk plugin is subject to remote code execution via craf… Patch available Fix from $4,9002026-08-17 HIGH 7.0 CVE-2026-18674 On a Kong Mesh global control plane, resources received over the zone-to-global KDS sync are attributed using the in-band, sender-controlled ControlP… Patch available Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-16467 Missing Authorization vulnerability in Dolusoft Software Technologies Fortilogger allows Accessing Functionality Not Properly Constrained by ACLs. T… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.0 CVE-2026-14564 Insufficiently Protected Credentials vulnerability in Innotim Software Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Retrieve … No fix yet Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-74843 A vulnerability was determined in Wavlink WN531P3 and WN535M1 V250922. Affected by this vulnerability is the function strcpy of the file /etc/lighttp… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74901 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in pqc.py where AES-GCM decryption failures trigger fallback to … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74900 openssl_encrypt versions before 1.4.0 contain a critical vulnerability in pqc.py where KEM decapsulation failures silently fall back to simulation mo… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74899 openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in IsolatedPluginExecutor that exposes Python type objects in restricted… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74896 openssl_encrypt versions before 1.4.0 contain a sandbox escape vulnerability in the DangerousPatternVisitor AST analyzer that fails to detect dunder … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74895 openssl_encrypt versions before 1.4.0 fail to apply sandbox restrictions in the default process isolation mode for plugin execution. Attackers can ex… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74894 openssl_encrypt before 1.4.0 contains an authentication bypass vulnerability in the verify_api_token function that accepts any non-empty Bearer token… No fix yet Fix from $5,7502026-08-17 HIGH 8.8 CVE-2026-74893 openssl_encrypt versions before 1.4.0 contain hardcoded default JWT signing secrets in config.py that pass validation checks. Attackers with access t… No fix yet Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-74892 openssl_encrypt versions before 1.4.0 contain a hardcoded default secret key in the standalone telemetry server configuration that is used for API ke… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-74891 openssl_encrypt versions before 1.4.0 contain hardcoded database credentials in standalone server configuration files. Attackers on the same network … No fix yet Fix from $5,7502026-08-17 MEDIUM 5.5 CVE-2026-74890 openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMAC tag generation and verifica… No fix yet Fix from $4,0002026-08-17 CRITICAL 9.8 CVE-2026-74889 openssl_encrypt versions before 1.4.0 use HKDF with no salt and static info parameter in key normalization functions, reducing entropy extraction and… No fix yet Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-74888 openssl_encrypt versions before 1.4.0 use a non-standard PBKDF2 key derivation construction with iterations=1 per call in an outer loop, creating a K… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-74886 openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules tha… No fix yet Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-74884 openssl_encrypt versions before 1.4.0 contain a path traversal vulnerability in the _is_safe_path method where the plugin_id parameter is not sanitiz… No fix yet Fix from $4,9002026-08-17 HIGH 8.8 CVE-2026-74883 openssl_encrypt versions before 1.4.0 contain a sandbox bypass vulnerability where the plugin sandbox fails to restrict alternative file access metho… No fix yet Fix from $4,9002026-08-17 HIGH 7.5 CVE-2026-74882 openssl_encrypt versions before 1.4.0 contain an insecure default configuration that trusts the entire RFC 1918 private address space in IntegrityPro… No fix yet Fix from $4,9002026-08-17 MEDIUM 6.5 CVE-2026-74881 openssl_encrypt versions before 1.4.0 configure CORS with allow_origins set to wildcard and allow_credentials enabled to true. Attackers can create m… No fix yet Fix from $4,0002026-08-17 CRITICAL 9.8 CVE-2026-74880 openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract t… No fix yet Fix from $5,7502026-08-17 HIGH 7.5 CVE-2026-74879 openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception str… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-74878 openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on … No fix yet Fix from $5,7502026-08-17 HIGH 8.8 CVE-2026-74877 openssl_encrypt versions before 1.4.0 contain a missing ownership verification vulnerability in the revoke_key method that allows authenticated clien… No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-74876 openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74875 openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata … No fix yet Fix from $5,7502026-08-17