Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.3
CVE-2025-67405

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password.

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-67404

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-67403

Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name.

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.5
CVE-2026-50782

Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.8
CVE-2026-13309

Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present …

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.1
CVE-2026-13308

Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.8
CVE-2026-13307

Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present a…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-13305

Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnera…

No fix yet
Fix from $1,600 2026-07-29
Unclassified CRITICAL 9.8
CVE-2025-65340

kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php.

No fix yet
Fix from $2,300 2026-07-29
Unclassified MEDIUM 6.1
CVE-2025-65337

Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field.

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.8
CVE-2026-6102

MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-5492

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-5491

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.8
CVE-2026-5490

DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-5489

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.5
CVE-2026-5487

DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-5057

ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-serv…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-5056

GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.4
CVE-2026-18266

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affe…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.8
CVE-2026-13268

G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate p…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.2
CVE-2026-12357

Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.6
CVE-2026-16328

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to overrid…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 10.0
CVE-2026-16326

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authen…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.7
CVE-2026-12935

The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occ…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-41939

Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows u…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified HIGH 7.0
CVE-2026-40272

Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-8339

A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authentica…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.2
CVE-2026-8338

A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malic…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.8
CVE-2026-64560

In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwo…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.8
CVE-2026-64559

In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer l…

No fix yet
Fix from $1,950 2026-07-29