Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Improper Input ValidationCWE-20 × clear
Webcenter Content HIGH 8.8
CVE-2026-60639

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.3
CVE-2026-60640

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

Mitigation only
Fix from $1,950 2026-07-21
Webcenter Content HIGH 8.8
CVE-2026-60633

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supported versions that are affected …

No fix yet
Fix from $1,950 2026-07-21
Jd Edwards Enterpriseone Configurator MEDIUM 6.4
CVE-2026-60620

Vulnerability in the JD Edwards EnterpriseOne Configurator product of Oracle JD Edwards (component: Configuration Management). The supported versio…

No fix yet
Fix from $1,600 2026-07-21
Peoplesoft Enterprise Campus Software Campus Community MEDIUM 6.6
CVE-2026-60613

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version th…

No fix yet
Fix from $1,600 2026-07-21
Peoplesoft Enterprise Campus Software Campus Community HIGH 8.8
CVE-2026-60603

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Australian Features). The supported version …

Mitigation only
Fix from $1,950 2026-07-21
Jdk MEDIUM 6.7
CVE-2026-60526

Vulnerability in Oracle Java SE (component: Installation). Supported versions that are affected are Oracle Java SE: 8u491 and 8u491-perf. Difficult…

No fix yet
Fix from $1,600 2026-07-21
Security Center HIGH 8.4
CVE-2026-64877

An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database.

Mitigation only
Fix from $1,950 2026-07-21
Buildkit HIGH 7.5
CVE-2026-15792

A malicious BuildKit client or frontend could craft a request that could lead to BuildKit daemon crashing with a panic.

Fix: 0.31.2+
Fix from $1,950 2026-07-21
Unclassified HIGH 8.7
CVE-2026-15724

In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal …

No fix yet
Fix from $1,950 2026-07-21
Firefox HIGH 7.5
CVE-2026-16378

Other issue in the DOM: Copy & Paste and Drag & Drop component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.

Fix: 153.0 / 153.0.0+
Fix from $1,950 2026-07-21
Unclassified HIGH 7.2
CVE-2026-1771

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all version…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 8.2
CVE-2026-47255

AgenticMail gives AI agents real email addresses and phone numbers. @agenticmail/api prior to version 0.9.32 and @agenticmail/core prior to version 0…

No fix yet
Fix from $1,950 2026-07-20
Mina Sshd MEDIUM 5.4
CVE-2026-58624

Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA SSHD is a Java library for client-side and server-side SSH. Component org.…

Fix: 2.19.0+
Fix from $1,600 2026-07-20
Unclassified HIGH 8.5
CVE-2026-47198

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperl…

No fix yet
Fix from $1,950 2026-07-20
Xrdp MEDIUM 5.3
CVE-2026-44978

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap out-of-bounds read vulnerability within the FIPS-specific receive paths. …

Fix: 0.10.6.1+
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-35048

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified MEDIUM 5.8
CVE-2026-63428

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id, name, value}]` array from th…

No fix yet
Fix from $1,600 2026-07-20
Meshtastic Firmware HIGH 7.5
CVE-2026-42566

Meshtastic is an open source mesh networking solution. Prior to version 2.7.23.b246bcd, a single node advertising a User.long_name that contains a ma…

No fix yet
Fix from $1,950 2026-07-20
Fastify\/http Proxy CRITICAL 10.0
CVE-2026-16117

Impact: @fastify/http-proxy versions up to and including 11.5.0 fail to rewrite the request prefix when the prefix segment is URL-encoded. Fastify's …

Fix: 11.6.0+
Fix from $2,300 2026-07-18
Langflow HIGH 8.8
CVE-2026-7755

IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration…

Fix: 1.10.1+
Fix from $1,950 2026-07-17
Ux MEDIUM 5.3
CVE-2026-49208

Symfony UX is a JavaScript ecosystem for Symfony. From 2.8.0 until 2.36.0 and 3.1.0, when a #[LiveProp] is typed as DateTimeInterface and no explicit…

Fix: 2.36.0+
Fix from $1,600 2026-07-17
Workplace Virtual Desktop Infrastructure HIGH 7.0
CVE-2026-53411

A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow…

Fix: 6.6.14+
Fix from $1,950 2026-07-16
Workplace Desktop CRITICAL 9.8
CVE-2026-53412

Improper Input Validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthentica…

Fix: 6.5.18 / 6.6.15+
Fix from $2,300 2026-07-16
Enterprise Gateway CRITICAL 9.8
CVE-2026-44180

Jupyter Enterprise Gateway launches remote Jupyter Notebook kernels across distributed clusters like Apache Spark, Kubernetes, and Docker Swarm. Vers…

Fix: 3.3.0+
Fix from $2,300 2026-07-16
Rooms HIGH 7.8
CVE-2026-53409

Improper Privilege Management in Zoom Rooms for Windows before version 7.1.0 may allow an authenticated user to conduct an escalation of privilege vi…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-33692

WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose c…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-54728

bunkerweb is an Open-source and next-generation Web Application Firewall (WAF). Prior to BunkerWeb 1.6.12 and BunkerWeb PRO 0.57, authenticated Host …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-46341

The Apify MCP server enables AI agents to extract data from websites using ready-made scrapers, crawlers, and automation tools available on the Apify…

No fix yet
Fix from $1,600 2026-07-16
Squid MEDIUM 5.5
CVE-2026-50012

Squid is a caching proxy for the Web. Prior to 7.6, due to an improper input validation bug in cache digest reply handling (peerDigestSwapInMask in s…

Fix: 7.6+
Fix from $1,600 2026-07-16