Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-76990 A vulnerability has been found in code-projects Simple Inventory System 1.0. Affected by this issue is some unknown functionality of the file /delete… No fix yet Fix from $4,9002026-08-20 HIGH 7.8 CVE-2026-76833 @cgauge/yaml npm package contains an arbitrary code execution vulnerability that allows attackers to execute arbitrary JavaScript by embedding a cust… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-76635 baserCMS before 5.3.0 contains a SQL injection vulnerability in BcDatabaseService.php that allows authenticated administrators to inject attacker-con… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.5 CVE-2026-76634 WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to acc… No fix yet Fix from $4,0002026-08-20 HIGH 8.1 CVE-2026-76633 WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their acco… No fix yet Fix from $4,9002026-08-20 HIGH 8.4 CVE-2026-70383 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information System Authority (RIA) DigiDoc4 … Patch available Fix from $4,9002026-08-20 MEDIUM 5.1 CVE-2026-64970 ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new account and enter a JavaScript pay… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-64969 ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authenticated user, including a stud… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.1 CVE-2026-64968 ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make the server request arbitrary i… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.9 CVE-2026-64967 A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access arbitrary files outside the i… No fix yet Fix from $4,0002026-08-20 HIGH 8.7 CVE-2026-64966 ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor privileges can upload and extract… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-64965 ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticated user (e.g. a student) enro… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-64964 ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due … No fix yet Fix from $4,0002026-08-20 MEDIUM 5.1 CVE-2026-64962 ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visi… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-64961 ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for… No fix yet Fix from $4,0002026-08-20 HIGH 8.7 CVE-2026-64960 ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are … No fix yet Fix from $4,9002026-08-20 CRITICAL 9.8 CVE-2026-15706 Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Appl… No fix yet Fix from $5,7502026-08-20 HIGH 8.4 CVE-2026-77118 A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances i… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-76989 A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the fi… Patch available Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-76988 A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_ope… Patch available Fix from $4,0002026-08-20 HIGH 7.3 CVE-2026-76987 A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute… Patch available Fix from $4,9002026-08-20 HIGH 7.6 CVE-2026-74011 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Inje… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.6 CVE-2026-28164 Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Eleme… No fix yet Fix from $5,7502026-08-20 MEDIUM 5.3 CVE-2026-28163 Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.0 CVE-2025-62306 HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflo… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.9 CVE-2025-62300 HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing … No fix yet Fix from $4,0002026-08-20 MEDIUM 6.6 CVE-2025-62299 HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the eleva… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-77085 n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied … No fix yet Fix from $4,0002026-08-20 HIGH 7.7 CVE-2026-77084 n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repositor… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.0 CVE-2026-77083 n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sa… No fix yet Fix from $4,0002026-08-20