Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-77014 A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-76610 Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing una… No fix yet Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-14952 An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional f… No fix yet Fix from $4,9002026-08-20 HIGH 8.0 CVE-2026-14951 An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages. No fix yet Fix from $4,9002026-08-20 CRITICAL 9.8 CVE-2026-14950 An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th… No fix yet Fix from $5,7502026-08-20 MEDIUM 6.5 CVE-2026-14949 A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to cr… No fix yet Fix from $4,0002026-08-20 HIGH 8.8 CVE-2026-14948 A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pl… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-14947 A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extra… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-14946 A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code executio… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-76569 Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4 No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-76565 Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7 No fix yet Fix from $4,0002026-08-20 HIGH 8.6 CVE-2026-76564 Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7 No fix yet Fix from $4,9002026-08-20 HIGH 8.6 CVE-2026-75948 Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and … No fix yet Fix from $4,9002026-08-20 HIGH 8.6 CVE-2025-14601 An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.1 CVE-2026-71368 F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operation… No fix yet Fix from $4,0002026-08-20 HIGH 7.1 CVE-2026-14163 In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable sn… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2025-14602 The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to ac… No fix yet Fix from $4,0002026-08-20 HIGH 7.5 CVE-2026-75963 The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.8 CVE-2026-75860 The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r… No fix yet Fix from $5,7502026-08-20 MEDIUM 6.8 CVE-2026-74992 The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does … No fix yet Fix from $4,0002026-08-20 MEDIUM 6.8 CVE-2026-19697 The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file … No fix yet Fix from $4,0002026-08-20 MEDIUM 6.8 CVE-2026-19615 The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allo… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-17153 The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the… No fix yet Fix from $4,0002026-08-20 HIGH 7.2 CVE-2026-15049 The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.6 CVE-2026-13405 The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.9 CVE-2026-76956 In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnera… Patch available Fix from $4,0002026-08-20 HIGH 7.8 CVE-2026-19582 In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buff… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.3 CVE-2026-76800 A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Exe… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-76799 A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/log… No fix yet Fix from $4,0002026-08-20 HIGH 7.3 CVE-2026-76795 A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. T… Patch available Fix from $4,9002026-08-20