Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.9
CVE-2026-51385

An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fet…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.9
CVE-2026-47134

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk p…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.9
CVE-2026-47133

ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-di…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.1
CVE-2026-47128

nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow acce…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-44510

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver-sid…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16324

A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.4
CVE-2026-12900

The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/i…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.5
CVE-2024-51316

The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51315

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51314

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg.

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51312

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg.

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-55219

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementatio…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-53596

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does …

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-53595

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{h…

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.5
CVE-2026-47198

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-47130

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR)…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.1
CVE-2026-47129

NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in …

Mitigation only
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-44585

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint acc…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-44583

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /ext…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-44509

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fix…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.1
CVE-2026-44508

Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's …

Mitigation only
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51313

The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg.

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.8
CVE-2024-51311

The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList.

No fix yet
Fix from $2,300 2026-07-20
Clinic HIGH 8.1
CVE-2026-13381

VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated…

No fix yet
Fix from $1,950 2026-07-20
Clinic HIGH 7.5
CVE-2026-13380

VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credent…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-63766

GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified HIGH 8.8
CVE-2026-53593

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.6
CVE-2026-53591

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject m…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-64194

Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 10…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-64193

Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose pars…

No fix yet
Fix from $2,300 2026-07-20