Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-61842

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration obj…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-61690

Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives t…

Patch available
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-53654

Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.5
CVE-2026-46343

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.en…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-44254

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMe…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.7
CVE-2026-44252

Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-pri…

Patch available
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.3
CVE-2026-19672

The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and …

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 7.2
CVE-2026-18430

HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete anothe…

Patch available
Fix from $4,900 2026-08-19
Vios HIGH 7.7
CVE-2026-16819

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-o…

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.1
CVE-2026-76203

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenti…

Patch available
Fix from $4,000 2026-08-19
Unclassified HIGH 8.7
CVE-2026-75956

Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly t…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.1
CVE-2026-75955

Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped …

No fix yet
Fix from $4,000 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-75954

Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated int…

No fix yet
Fix from $5,750 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-75951

Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-75950

Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attac…

No fix yet
Fix from $4,000 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-75949

Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a clien…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-71961

Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrar…

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.1
CVE-2026-71960

Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authenticat…

No fix yet
Fix from $5,750 2026-08-19
Openmanage Enterprise HIGH 8.8
CVE-2026-71176

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')…

Fix: 4.7.0+
Fix from $4,900 2026-08-19
Command Update MEDIUM 6.5
CVE-2026-67268

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged …

Fix: 5.7.1+
Fix from $4,000 2026-08-19
Command Update MEDIUM 5.5
CVE-2026-67267

Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerabili…

Fix: 5.7.1+
Fix from $4,000 2026-08-19
Command Update MEDIUM 5.5
CVE-2026-67266

Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access cou…

Fix: 5.7.1+
Fix from $4,000 2026-08-19
Command Update HIGH 8.8
CVE-2026-58565

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Command Update HIGH 7.8
CVE-2026-58564

Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local acce…

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Command Update HIGH 7.3
CVE-2026-58562

Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could …

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Command Update HIGH 7.3
CVE-2026-56797

Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with…

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Command Update MEDIUM 6.6
CVE-2026-56796

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low pr…

Fix: 5.7.1+
Fix from $4,000 2026-08-19
Openmanage Enterprise MEDIUM 5.4
CVE-2026-54793

Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')…

Fix: 4.7.0+
Fix from $4,000 2026-08-19
Command Update HIGH 7.8
CVE-2026-53477

Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attac…

Fix: 5.7.1+
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-53452

Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the…

Patch available
Fix from $4,000 2026-08-19