Vulnerability index

Browse CVEs

4,950 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness InjectionCWE-74 × clear
HIGH 7.3 CVE-2026-7063 A vulnerability was detected in code-projects Employee Management System 1.0. This vulnerability affects unknown code of the file /370project/process… Mitigation only Fix from $1,9502026-04-26 HIGH 7.3 CVE-2026-7058 A vulnerability has been found in 666ghj MiroFish up to 0.1.2. The impacted element is the function SimulationIPCClient.send_command of the file back… Mitigation only Fix from $1,9502026-04-26 HIGH 7.3 CVE-2026-7060 A vulnerability was determined in liyupi yu-picture up to a053632c41340152bf75b66b3c543d129123d8ec. This impacts the function PageRequest of the file… Patch available Fix from $1,9502026-04-26 MEDIUM 6.3 CVE-2026-7045 A vulnerability was determined in baomidou dynamic-datasource 2.5.0. Affected by this vulnerability is the function DsSpelExpressionProcessor#doDeter… Patch available Fix from $1,6002026-04-26 HIGH 7.8 CVE-2026-7039 A security vulnerability has been detected in tufantunc ssh-mcp up to 1.5.0. The affected element is the function shell.write of the file src/index.t… Mitigation only Fix from $1,9502026-04-26 HIGH 8.8 CVE-2026-7023 A vulnerability was detected in ByteDance coze-studio up to 0.5.1. Affected by this vulnerability is the function ExecuteSQL of the file backend/doma… Coze Studio after 0.5.1 Fix from $1,9502026-04-26 HIGH 7.3 CVE-2026-7002 A vulnerability was determined in KLiK SocialMediaWebsite up to 1.0.1. This vulnerability affects unknown code of the file /includes/get_message_ajax… Mitigation only Fix from $1,9502026-04-25 MEDIUM 6.3 CVE-2026-6994 A weakness has been identified in Envoy up to 1.33.0. Affected is the function params.add of the file source/extensions/filters/http/header_mutation/… Patch available Fix from $1,6002026-04-25 MEDIUM 6.3 CVE-2026-6991 A vulnerability was determined in colinhacks Zod up to 4.3.6. The impacted element is an unknown function of the file packages/zod/src/v4/core/regexe… Mitigation only Fix from $1,6002026-04-25 HIGH 8.8 CVE-2026-6989 A vulnerability has been found in Tenda F453 up to 1.0.0.3. Impacted is the function TendaTelnet of the file /goform/telnet of the component Telnet S… F453 Firmware No fix yet Fix from $1,9502026-04-25 CRITICAL 9.8 CVE-2026-6987 A vulnerability was detected in PicoClaw up to 0.2.4. Impacted is an unknown function of the file /api/gateway/restart of the component Web Launcher … Picoclaw after 0.2.4 Fix from $2,3002026-04-25 MEDIUM 6.3 CVE-2026-6982 A vulnerability was determined in star7th ShowDoc up to 2.10.10/3.6.2/3.8.0. Affected by this vulnerability is an unknown functionality of the file s… Mitigation only Fix from $1,6002026-04-25 HIGH 7.3 CVE-2026-6980 A vulnerability has been found in Divyanshu-hash GitPilot-MCP up to 9ed9f153ba4158a2ad230ee4871b25130da29ffd. This impacts the function repo_path of … Mitigation only Fix from $1,9502026-04-25 MEDIUM 5.9 CVE-2026-41319 MailKit is a cross-platform mail client library built on top of MimeKit. A STARTTLS Response Injection vulnerability in versions prior to 4.16.0 allo… Mailkit 4.16.0+ Fix from $1,6002026-04-24 MEDIUM 6.3 CVE-2026-6799 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config… Mitigation only Fix from $1,6002026-04-21 MEDIUM 5.4 CVE-2026-0972 HTML injection is possible in system generated emails in Fortra's GoAnywhere MFT prior to 7.10.0. Note: The title, details, and description of this… Goanywhere Managed File Transfer 7.10.0+ Fix from $1,6002026-04-21 MEDIUM 6.5 CVE-2026-1089 User‑Controlled HTTP Header in Fortra's GoAnywhere MFT prior to version 7.10.0 allows attackers to trigger a DNS lookup, as well as DNS Rebinding and… Goanywhere Managed File Transfer 7.10.0+ Fix from $1,6002026-04-21 HIGH 7.3 CVE-2026-6629 A vulnerability has been found in Metasoft 美特软件 MetaCRM up to 6.4.0. This vulnerability affects the function Statement.executeUpdate of the file … Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6628 A flaw has been found in phili67 Ecclesia CRM up to 8.0.0. This affects the function ValidateInput of the file /v2/query/view/ of the component Query… Mitigation only Fix from $1,6002026-04-20 HIGH 7.3 CVE-2026-6603 A vulnerability was determined in modelscope agentscope up to 1.0.18. Affected by this vulnerability is the function execute_python_code/execute_shel… Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6599 A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file s… Mitigation only Fix from $1,6002026-04-20 HIGH 7.3 CVE-2026-6595 A vulnerability was identified in ProjectsAndPrograms School Management System up to 6b6fae5426044f89c08d0dd101c7fa71f9042a59. This vulnerability aff… Mitigation only Fix from $1,9502026-04-20 MEDIUM 6.3 CVE-2026-6576 A vulnerability was determined in liangliangyy DjangoBlog up to 2.1.0.0. The affected element is the function CommandHandler of the file servermanage… Mitigation only Fix from $1,6002026-04-19 HIGH 7.3 CVE-2026-6562 A flaw has been found in dameng100 muucmf 1.9.5.20260309. Impacted is the function getListByPage of the file /index/Search/index.html. Executing a ma… Mitigation only Fix from $1,9502026-04-19 HIGH 7.3 CVE-2026-6490 A weakness has been identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. Impacted is an unknown function of the file admin/del… Mitigation only Fix from $1,9502026-04-17 MEDIUM 6.3 CVE-2026-6488 A vulnerability was identified in QueryMine sms up to 7ab5a9ea196209611134525ffc18de25c57d9593. This vulnerability affects unknown code of the file a… Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-5797 The Quiz And Survey Master plugin for WordPress is vulnerable to Arbitrary Shortcode Execution in versions up to and including 11.1.0. This is due to… Mitigation only Fix from $1,6002026-04-17 MEDIUM 5.3 CVE-2026-6219 A vulnerability was determined in aandrew-me ytDownloader up to 3.20.2. This affects the function child_process.exec of the file src/compressor.js of… No fix yet Fix from $1,6002026-04-13 MEDIUM 6.3 CVE-2026-6202 A security flaw has been discovered in code-projects Easy Blog Site 1.0. This affects an unknown function of the file post.php. Performing a manipula… Mitigation only Fix from $1,6002026-04-13 MEDIUM 6.3 CVE-2026-6191 A vulnerability was determined in itsourcecode Construction Management System 1.0. This affects an unknown function of the file /equipments.php. Exec… Mitigation only Fix from $1,6002026-04-13