Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-60085

PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocke…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 6.3
CVE-2026-59254

n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outsi…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.8
CVE-2026-58655

The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.8
CVE-2026-57996

phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 10.0
CVE-2026-56699

Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to in…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 6.4
CVE-2026-56352

n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files fr…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 6.3
CVE-2026-56349

n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instruct…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 7.5
CVE-2026-56339

Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-58077

Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.6
CVE-2026-57833

Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-57832

Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthe…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.7
CVE-2026-57831

Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulne…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.8
CVE-2026-15804

The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, ther…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.6
CVE-2026-15583

A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana serv…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.7
CVE-2026-14251

A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objec…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.8
CVE-2026-42936

The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected inst…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.6
CVE-2026-12512

The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowi…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.1
CVE-2026-12281

The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treatin…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.5
CVE-2026-11580

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-dupli…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified MEDIUM 5.3
CVE-2026-11579

The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing f…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.5
CVE-2026-8920

Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 7.2
CVE-2026-8919

Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing …

Mitigation only
Fix from $1,950 2026-07-15
Unclassified MEDIUM 5.6
CVE-2026-15030

Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified HIGH 8.4
CVE-2026-15029

Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administra…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified HIGH 8.2
CVE-2026-13585

Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Inter…

Mitigation only
Fix from $1,950 2026-07-15
Unclassified CRITICAL 9.5
CVE-2026-13385

An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M…

Mitigation only
Fix from $2,300 2026-07-15
Unclassified MEDIUM 5.9
CVE-2026-11851

Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models al…

Mitigation only
Fix from $1,600 2026-07-15
Unclassified CRITICAL 9.8
CVE-2026-5270

An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue…

Mitigation only
Fix from $2,300 2026-07-14
Unclassified CRITICAL 9.8
CVE-2026-5269

In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operation…

No fix yet
Fix from $2,300 2026-07-14
Unclassified MEDIUM 6.5
CVE-2026-36035

Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat…

Mitigation only
Fix from $1,600 2026-07-14