Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-47227

Admidio is an open-source user management solution. `modules/categories.php` checks that the supplied `type` parameter (`ANN`, `EVT`, `ROL`, `USF`, ……

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.3
CVE-2026-16999

Improper restriction of XML external entity reference vulnerability in Ministry of Justice UYAP Document Editor allows Serialized Data External Linki…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 7.5
CVE-2025-59325

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to encrypt the initramfs contents, allowing for the offline recovery of secrets and cryp…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2025-59327

In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4, bootxsa.efi fails to properly validate LUKS encryption and, if encryption is present, all …

No fix yet
Fix from $4,900 2026-08-12
Unclassified CRITICAL 9.8
CVE-2025-59326

CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails to enforce IMA policy protections across temporary file systems, allowing for unsigned c…

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-71408

A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 a…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.6
CVE-2026-71407

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-70468

A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManag…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-70466

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all version…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.9
CVE-2026-57858

Cal.com Cal.diy versions 2.1.1 through 6.2.0 contain a stored cross-site scripting vulnerability in the BookingPageTagManager component that allows a…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.0
CVE-2026-53996

NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to i…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-47226

Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-26035

An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4…

No fix yet
Fix from $5,750 2026-08-12
Unclassified MEDIUM 5.4
CVE-2026-70560

Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attacke…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.1
CVE-2026-70465

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClien…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-17008

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and …

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-16990

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-suppli…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-16747

The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input th…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-16621

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an orde…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-15213

The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback:…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-15045

The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored…

No fix yet
Fix from $4,000 2026-08-12
Unclassified HIGH 8.8
CVE-2026-11325

Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execu…

No fix yet
Fix from $4,900 2026-08-12
Unclassified MEDIUM 5.3
CVE-2026-67284

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform vario…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.1
CVE-2026-64955

When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. …

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.5
CVE-2026-64952

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned …

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 5.9
CVE-2026-18663

A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control…

No fix yet
Fix from $4,000 2026-08-12
Unclassified MEDIUM 6.9
CVE-2026-67283

Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform var…

No fix yet
Fix from $4,000 2026-08-12
Unclassified CRITICAL 10.0
CVE-2026-67282

Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code …

No fix yet
Fix from $5,750 2026-08-12
Unclassified HIGH 8.2
CVE-2026-19426

POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the syst…

No fix yet
Fix from $4,900 2026-08-12
Unclassified HIGH 7.5
CVE-2025-41770

An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt acc…

No fix yet
Fix from $4,900 2026-08-12