Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.4
CVE-2026-12504

Improper Authentication (CWE-287) in the PAM configuration in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 …

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.2
CVE-2026-12503

Improper Link Resolution (CWE-59) in `/usr/bin/larm_starter` in Loytec L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A6…

No fix yet
Fix from $2,300 2026-07-24
Unclassified HIGH 8.4
CVE-2026-12502

Improper Privilege Management (CWE-269) in `/usr/bin/ltsudo` in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.1…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.7
CVE-2026-12496

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD t…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-17048

A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requ…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.1
CVE-2026-9765

Note: The CVE and blog post don't exist because we determined this is actually a cloud-only issue. Access Controls are “Broken” when a user can acce…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-7484

External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Cons…

No fix yet
Fix from $1,600 2026-07-24
Neethi HIGH 7.5
CVE-2026-66143

It is possible to bypass the maximum number of normalized policy alternatives that was introduced in Apache Neethi 3.2.2 via certain crafted policies…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.3
CVE-2026-66009

Parse Server versions >= 9.0.0 before 9.10.0-alpha.5 and >= 8.2.2 before 8.6.86 return GraphQL validation error messages that name required custom in…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.3
CVE-2026-66008

Parse Server versions >= 9.0.0 before 9.10.0-alpha.6 and >= 8.2.2 before 8.6.87 disclose Pointer and Relation target class names through GraphQL vali…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-16743

A flaw was found in accountsservice. The systemd-homed code path for SetIconFile opens a user-supplied filename as root without the validation and pr…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-16730

A flaw was found in dbus-broker. When the process file-descriptor limit is reached, EMFILE/ENFILE errors during peer setup (notably SO_PEERPIDFD) are…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.7
CVE-2026-15810

A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28,…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.4
CVE-2026-15243

Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or reg…

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.5
CVE-2026-10610

Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user.

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.5
CVE-2026-7483

Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user.

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.8
CVE-2026-16634

TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has…

Mitigation only
Fix from $2,300 2026-07-24
Unclassified HIGH 7.2
CVE-2026-15401

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 7.3
CVE-2026-10033

The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the p…

No fix yet
Fix from $1,950 2026-07-24
Unclassified CRITICAL 9.3
CVE-2026-24727

An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System …

No fix yet
Fix from $2,300 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15821

The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in al…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15739

The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all ve…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.1
CVE-2026-15346

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.1
CVE-2026-12702

In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment.

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-16910

A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs withou…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.3
CVE-2026-16519

A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link librar…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15755

The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versio…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15665

The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Sh…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15653

The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backen…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15648

The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, a…

No fix yet
Fix from $1,600 2026-07-24