Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2024-23574

HCL Aftermarket EPC is vulnerable to attack since It was found that a malicious actor can use brute-force techniques to either guess or confirm valid…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2024-23568

HCL Aftermarket EPC is vulnerable to attacks since the server software version used by the application is revealed by the web server. Displaying vers…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2024-23566

HCL Aftermarket EPC is vulnerable to brute force attacks since application doesn’t have captcha implemented. It can lead to various security issues l…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2024-23565

HCL Aftermarket EPC is vulnerable to email flooding as the application does not have a proper mail limitation mechanism at Forget Password functional…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.1
CVE-2024-23564

HCL Aftermarket EPC is affected by Business Logic Vulnerability using which a non valid user of the application can obtain passwords from the server …

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 7.5
CVE-2026-8396

Improper restriction of XML external entity reference vulnerability in Netcad Software Inc. NetGIS allows Serialized Data External Linking. This iss…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-7189

Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly …

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.3
CVE-2026-16014

A vulnerability was found in code-projects Hospital Bed Management System 1.0. This affects an unknown part of the component Login Form. Performing a…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-16009

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /prescriptionorderdetail.php…

No fix yet
Fix from $1,600 2026-07-17
Build Of Keycloak MEDIUM 5.5
CVE-2026-15943

A flaw was found in the Keycloak keycloak-services component, which handles the management of identity providers. The issue occurs when a delegated a…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.1
CVE-2026-22104

Improper access control in Hashtopolis server web-interface chunk activity component for versions prior to 0.14.8 allows any created account to read …

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.1
CVE-2026-15380

A non-administrator interactive user can obtain full SYSTEM code execution through a DCOM/task scheduler logic chain — no network access, no memory c…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.1
CVE-2026-15379

The Altiris WMI provider exposes a class (AltirisAgent_Stream) that allows any local standard user to read the contents of any file accessible to the…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-9810

The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator …

Mitigation only
Fix from $2,300 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-13402

The Royal Addons for Elementor WordPress plugin before 1.7.1063 does not check the post status of menu items or the templates they reference in one …

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.4
CVE-2026-12393

The WPS Bookings for WooCommerce WordPress plugin before 3.11.7 does not verify that a booking order belongs to the requesting user before cancelling…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-11966

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membe…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.1
CVE-2026-11961

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is …

Mitigation only
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-11575

The PhonePe Payment Solutions WordPress plugin before 3.1.0 does not properly verify the authenticity of incoming payment callbacks: the secret used …

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-10525

The NEX-Forms WordPress plugin before 9.2.3 does not sanitise and escape some submitted form data before storing it and outputting it back in the ad…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.3
CVE-2019-25764

**UNSUPPORTED WHEN ASSIGNED**  Exposed IOCTL with Insufficient Access Control in the ASUS AURA SYNC driver allows a local user to bypass the driver's…

No fix yet
Fix from $1,950 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-15982

The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Automation Toolkit plugin for WordPress is vulnerable to Privilege Escalation in al…

Mitigation only
Fix from $2,300 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-15094

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' parameter in all versions up to, an…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-60060

Improper Handling of Length Parameter Inconsistency (CWE-130) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When T…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-58317

Unsigned to Signed Conversion Error (CWE-196) vulnerability exists in TTSSH2 plugin of Tera Term provided by TeraTerm Project. When Tera Term attempt…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-21770

HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hijacking vulnerability which could allow an attacker to modify or replace the appl…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-15759

The ChatHelp – Click to Chat Button, WooCommerce Chat to Order & Floating Chat Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-15161

The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-14503

The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.5
CVE-2026-13765

The LearnPress – WordPress LMS Plugin for Create and Sell Online Courses plugin for WordPress is vulnerable to Sensitive Information Exposure in all …

No fix yet
Fix from $1,950 2026-07-17