Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-63771

Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values th…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.8
CVE-2026-63108

Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/deny…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.1
CVE-2026-62414

Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.1
CVE-2026-61901

Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect.

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.7
CVE-2026-63107

LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authen…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-61900

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-61425

Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, poten…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-61424

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vuln…

No fix yet
Fix from $2,300 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-60034

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS …

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 5.1
CVE-2026-60033

Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulne…

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.4
CVE-2026-60032

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authentic…

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.9
CVE-2026-60031

Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.7
CVE-2026-60030

Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.1
CVE-2026-60029

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable …

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.6
CVE-2026-60028

Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-60027

Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.9
CVE-2026-60026

Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vul…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-8170

The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-8169

ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated usi…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-64612

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery hand…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-45295

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/…

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.3
CVE-2026-39878

Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified HIGH 7.5
CVE-2026-34239

Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is p…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.1
CVE-2026-26483

Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The applicat…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-50743

A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be t…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-47276

In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broke…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.6
CVE-2026-40187

In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTem…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-39879

Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/mod…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-39385

Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using u…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-35217

NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Opti…

No fix yet
Fix from $1,600 2026-07-20