Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.8
CVE-2026-70370

Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directl…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-70369

Koha's reports/acquisitions_stats.pl builds its per-cell statistics query in sub calculate by interpolating the user-controlled Filter request parame…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-18809

Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153.0.3.

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.1
CVE-2026-18806

External control of file name or path vulnerability in TÜBİTAK BİLGEM Software Technologies Research Institute pardus-image-writer allows Removing Im…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.8
CVE-2026-10710

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::ExtractDrive…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.8
CVE-2026-10709

A maliciously crafted FBX file, when parsed through Autodesk FBX SDK, can trigger a stack-based buffer overflow vulnerability in fbxsdk::FbxIO::Binar…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-15721

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows S…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified HIGH 7.4
CVE-2026-14838

Use of GET request method with sensitive query strings vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resour…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-14804

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sen…

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14465

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Reusing Sess…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14219

URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-14202

Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Account Foot…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14194

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Informatics Consultancy Inc. HUMAN…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14192

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and Informatics Consultancy Inc.…

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified HIGH 7.2
CVE-2026-67243

freo2 provided by refirio contains an unrestricted upload of file with dangerous type vulnerability. A user with the highest-level administrative pri…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.5
CVE-2026-18759

The background service of ABP or AES runs as NT AUTHORITY\SYSTEM and implements a file-based inter-process communication (IPC) mechanism protected by…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-18755

A DLL hijacking vulnerability in GeoVision GV-ASManager allows a local attacker with write access to an unsafe search directory to execute arbitrary …

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-18754

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private k…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-18753

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private k…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-64564

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_a…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.8
CVE-2026-64563

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-64562

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-64561

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Ch…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.0
CVE-2026-16623

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, al…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file…

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-16548

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-16547

The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-16536

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-16293

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which…

No fix yet
Fix from $1,600 2026-08-04