Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.4
CVE-2026-12693

Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly…

No fix yet
Fix from $2,300 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-12692

Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Vide…

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 7.5
CVE-2026-12691

Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affec…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-11763

Authorization bypass through User-Controlled key vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Services Inc. Gi…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63100

Maybe through 0.6.0 contains a missing authorization vulnerability that allows authenticated low-privilege member-role users to access and modify glo…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63099

TheHive through 4.1.24 contains a broken object-level authorization vulnerability in the attachment download endpoints that allows any authenticated …

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.8
CVE-2026-60025

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0 had an fro…

No fix yet
Fix from $1,950 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-60024

Joomla Extension - joomdonation.com - Insecure default configuration Events Booking < 5.8.0 - The Joomla extension Events Booking prior version 5.8.0…

No fix yet
Fix from $2,300 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-58149

Joomla Extension - joomdonation.com - User enumeration in Events Booking < 5.8.0 - The Joomla extension Events Booking is vulnerable to an unauthenti…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.8
CVE-2026-63096

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to cause the server to open outbou…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-63095

Dendrite through 0.13.8 contains an improper authorization vulnerability in the Matrix Client-Server API that allows any authenticated local user to …

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.7
CVE-2026-58148

Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-15783

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user with write access to any reposito…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.6
CVE-2026-15343

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an attacker who had code execution inside the Dependabot updat…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.7
CVE-2026-15007

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to cause service disruption by supply…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.1
CVE-2026-14871

osTicket versions v1.18.3 and v1.17.7 contain a Broken Object Level Authorization (BOLA) leading to Insecure Direct Object Reference (IDOR) in the AJ…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 8.5
CVE-2026-12715

Missing Authorization in Google Cloud Firebase Studio versions prior to 2026-04-15 on Google Cloud Platform allows an attacker to download other user…

Mitigation only
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-51083

Incorrect access control in Proxmox Virtual Environment (PVE) 9.x qemu-server before 9.1.8 and 8.x before 8.4.8 allows users within limited privilege…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.2
CVE-2026-51082

A race condition between the vncproxy and vncwebsocket API calls in Proxmox Virtual Environment (PVE) 9.x pve-manager before 9.1.9 and 8.x before 8.4…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-51081

A cross-site scripting (XSS) vulnerability in Proxmox Virtual Environment (PVE) 9.x 5.1.8 and Proxmox Virtual Environment (PVE) 8.x 4.3.16 allows att…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 5.9
CVE-2026-16089

A flaw was found in the keycloak-services component of Red Hat Build of Keycloak. The issue occurs because OAuth 2.0 authorization codes are not prop…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16017

A security flaw has been discovered in mosaxiv clawlet up to 0.2.10. Impacted is the function list/remove of the file tools/tool_cron.go of the compo…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-12705

Missing support for integrity check vulnerability in ABB KNX Update Tool (ABB), ABB KNX Update Tool (BJE). This issue affects KNX Update Tool (ABB):…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.5
CVE-2026-9592

SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, a…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-7488

Insertion of sensitive information into sent data vulnerability in IKAS Technology Inc. E-Commerce allows Retrieve Embedded Sensitive Data. This iss…

No fix yet
Fix from $1,950 2026-07-17
Libpve Storage Perl CRITICAL 9.8
CVE-2026-51080

libpvestorage-perl v9.1.1 and libpve-storage-perl v8.3.7 were discovered to contain an XML External Entity (XXE) vulnerability.

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 7.3
CVE-2026-16016

A vulnerability was identified in poco-ai poco-claw up to 0.5.4. This issue affects the function run_task of the file executor/app/api/v1/task.py. Th…

No fix yet
Fix from $1,950 2026-07-17
Epp Management HIGH 8.1
CVE-2025-60357

AhnLab EPP Management v1.0.14.32-6249 was discovered to contain a NoSQL injection vulnerability via the eventlog/agentEvent/list endpoint.

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.3
CVE-2024-42214

HCL Aftermarket EPC is vulnerable to attack since HTTP OPTIONS method is enabled on this web server. The OPTIONS method provides a list of the method…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2024-23575

HCL Aftermarket EPC is vulnerable to attack since the application returns detailed error messages that leak information about the processing on the s…

No fix yet
Fix from $1,600 2026-07-17