Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-35048

The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat…

Mitigation only
Fix from $2,300 2026-07-20
Unclassified HIGH 7.3
CVE-2026-32825

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-32824

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.1
CVE-2026-32821

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32820

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32806

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 5.4
CVE-2026-6793

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT …

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.9
CVE-2026-51027

An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component.

Mitigation only
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-51026

Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request.

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 10.0
CVE-2026-46412

@beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UT…

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 6.1
CVE-2026-32822

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.5
CVE-2026-32807

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-27823

A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.8
CVE-2026-25039

Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creat…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.8
CVE-2026-21824

HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of u…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.7
CVE-2026-45270

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` …

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-45139

CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.5
CVE-2026-16277

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information r…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16252

A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.0
CVE-2026-12701

A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but…

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 5.3
CVE-2026-57311

Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Cod…

No fix yet
Fix from $1,600 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-57310

Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to …

No fix yet
Fix from $1,600 2026-07-20
Unclassified CRITICAL 9.3
CVE-2026-57309

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in…

No fix yet
Fix from $2,300 2026-07-20
Unclassified HIGH 8.8
CVE-2026-16248

A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of t…

No fix yet
Fix from $1,950 2026-07-20
Unclassified MEDIUM 6.3
CVE-2026-16244

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality…

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 7.3
CVE-2026-12080

A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command ha…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 8.6
CVE-2026-64623

Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accep…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.5
CVE-2026-64622

Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox …

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16247

In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %P…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.3
CVE-2026-16246

In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full…

No fix yet
Fix from $1,950 2026-07-20