Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2025-45870

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.0
CVE-2026-10587

A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode.

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-63082

Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.4
CVE-2026-63081

Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated att…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.6
CVE-2026-57206

SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.8
CVE-2026-12379

An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not prop…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.8
CVE-2025-45868

LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to ma…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-59862

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descrip…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.3
CVE-2026-14254

A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentic…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-5674

A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploi…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-9494

An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT …

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.6
CVE-2026-63306

stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrar…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.1
CVE-2026-63305

AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are conca…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.1
CVE-2026-63304

AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function in…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.0
CVE-2026-12391

An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.0
CVE-2026-11386

An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so…

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2023-49900

An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command.

No fix yet
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.8
CVE-2023-49899

An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channe…

Mitigation only
Fix from $2,300 2026-07-16
Unclassified CRITICAL 9.6
CVE-2026-22752

Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serv…

No fix yet
Fix from $2,300 2026-07-16
Unclassified HIGH 7.2
CVE-2026-7543

The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 d…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.7
CVE-2026-6424

Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.5
CVE-2026-6423

A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel.

Mitigation only
Fix from $1,950 2026-07-16
Unclassified HIGH 8.7
CVE-2026-58078

Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vu…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.3
CVE-2026-15106

The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up t…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.8
CVE-2026-15103

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitr…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-15099

The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and includ…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.5
CVE-2026-15022

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all …

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.4
CVE-2026-15021

The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including,…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.1
CVE-2026-15008

The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletio…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.8
CVE-2026-15005

The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missi…

Mitigation only
Fix from $1,950 2026-07-16