Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-61842 Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to return the raw configuration obj… Patch available Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-61690 Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipArchiver.php passes archives t… Patch available Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-53654 Grav is a file-based Web platform. Prior to 3.8.5, the Login plugin twofa_cancel task accepts a client-controlled _redirect field without a nonce and… Patch available Fix from $4,0002026-08-19 HIGH 7.5 CVE-2026-46343 Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.6 and 5.0.0-beta2, WazuhCommon.en… Patch available Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-44254 Wazuh is a free and open source platform used for threat prevention, detection, and response. From 1.0.0 until 4.14.6 and 5.0.0-beta2, HandleSecureMe… Patch available Fix from $4,0002026-08-19 HIGH 7.7 CVE-2026-44252 Wazuh is a free and open source platform used for threat prevention, detection, and response. From 4.0.0 until 4.14.5, Wazuh Manager allows a low-pri… Patch available Fix from $4,9002026-08-19 MEDIUM 6.3 CVE-2026-19672 The tarfile module's tar and data extraction filters created directories outside the destination for members whose name leaves the destination and … Patch available Fix from $4,0002026-08-19 HIGH 7.2 CVE-2026-18430 HumHub 1.18.4 contains a stored cross-site scripting vulnerability in the comment-deletion notification flow. A Space administrator can delete anothe… Patch available Fix from $4,9002026-08-19 HIGH 7.7 CVE-2026-16819 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service and compromise data integrity due to a time-o… Vios 4.1.0.50 / 4.1.1.30+ Fix from $4,9002026-08-19 MEDIUM 5.1 CVE-2026-76203 Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenti… Patch available Fix from $4,0002026-08-19 HIGH 8.7 CVE-2026-75956 Joomla Extension - cmsjunkie.com - DOS vector in pagination parameter handling in J-BusinessDirectory < 6.2.3 - Pagination values were not strictly t… No fix yet Fix from $4,9002026-08-19 MEDIUM 5.1 CVE-2026-75955 Joomla Extension - cmsjunkie.com - Reflected XSS / XML injection in J-BusinessDirectory < 6.2.3 - companyName from the request was written unescaped … No fix yet Fix from $4,0002026-08-19 CRITICAL 9.3 CVE-2026-75954 Joomla Extension - cmsjunkie.com - SQL injection in trips search in J-BusinessDirectory < 6.2.3 - Search keywords and ORDER BY were concatenated int… No fix yet Fix from $5,7502026-08-19 MEDIUM 6.9 CVE-2026-75951 Joomla Extension - cmsjunkie.com - Insecure Direct Object Reference (multiple frontend/API actions) in J-BusinessDirectory < 6.2.3 No fix yet Fix from $4,0002026-08-19 MEDIUM 6.9 CVE-2026-75950 Joomla Extension - cmsjunkie.com - Unauthenticated listing ownership takeover in J-BusinessDirectory < 6.2.3 - Ownership could be changed using attac… No fix yet Fix from $4,0002026-08-19 CRITICAL 10.0 CVE-2026-75949 Joomla Extension - cmsjunkie.com - Arbitrary file upload / deletion (path traversal) in J-BusinessDirectory < 6.2.3 - Upload/remove accepted a clien… No fix yet Fix from $5,7502026-08-19 HIGH 8.8 CVE-2026-71961 Cudy WR3000 2.0 running firmware before 2.5.24 contains an OS command injection vulnerability that allows authenticated attackers to execute arbitrar… No fix yet Fix from $4,9002026-08-19 CRITICAL 9.1 CVE-2026-71960 Cudy WR3000 2.0 running firmware before 2.5.24 contains a hard-coded JWT HMAC signing secret vulnerability in the Mosquitto MQTT broker's authenticat… No fix yet Fix from $5,7502026-08-19 HIGH 8.8 CVE-2026-71176 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')… Openmanage Enterprise 4.7.0+ Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-67268 Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged … Command Update 5.7.1+ Fix from $4,0002026-08-19 MEDIUM 5.5 CVE-2026-67267 Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerabili… Command Update 5.7.1+ Fix from $4,0002026-08-19 MEDIUM 5.5 CVE-2026-67266 Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access cou… Command Update 5.7.1+ Fix from $4,0002026-08-19 HIGH 8.8 CVE-2026-58565 Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could … Command Update 5.7.1+ Fix from $4,9002026-08-19 HIGH 7.8 CVE-2026-58564 Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local acce… Command Update 5.7.1+ Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-58562 Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could … Command Update 5.7.1+ Fix from $4,9002026-08-19 HIGH 7.3 CVE-2026-56797 Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with… Command Update 5.7.1+ Fix from $4,9002026-08-19 MEDIUM 6.6 CVE-2026-56796 Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low pr… Command Update 5.7.1+ Fix from $4,0002026-08-19 MEDIUM 5.4 CVE-2026-54793 Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')… Openmanage Enterprise 4.7.0+ Fix from $4,0002026-08-19 HIGH 7.8 CVE-2026-53477 Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attac… Command Update 5.7.1+ Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-53452 Ground Station is a browser-based suite for satellite tracking, SDR reception, hardware control, and telemetry decoding. Prior to version 0.4.13, the… Patch available Fix from $4,0002026-08-19