Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.2
CVE-2026-22098

Various sensitive information such as passwords and charging card UIDs are written to log files.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22097

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability t…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22096

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or up…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22095

The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.5
CVE-2026-22093

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an …

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15557

A weakness has been identified in waooAI waoowaoo up to 0.4.1. Affected by this vulnerability is the function getInternalTaskSession/getAuthSession/r…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-15548

A security vulnerability has been detected in Shibby Tomato up to 1.28.0000. This vulnerability affects the function sub_407220 of the file /usr/sbin…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.2
CVE-2026-13014

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrari…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 7.5
CVE-2026-15574

A flaw was found in the vllm-orchestrator-gateway component. The system's production binary logs all incoming authorization headers and full chat pay…

No fix yet
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15547

A weakness has been identified in Shibby Tomato up to 1.28.0000. This affects the function sub_2D048 of the component CIFS Mount Handler. Executing a…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15546

A security flaw has been discovered in Shibby Tomato up to 1.28.0000. Affected by this issue is the function sub_2D568 of the component start_jffs2. …

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 8.8
CVE-2026-15545

A vulnerability was identified in Shibby Tomato up to 1.28.0000. Affected by this vulnerability is the function main of the file www/apcupsd/tomatoda…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified CRITICAL 9.6
CVE-2026-14453

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-4769

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionalit…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 8.8
CVE-2026-15544

A vulnerability was determined in Shibby Tomato up to 1.28.0000. Affected is the function getupsvar of the file www/apcupsd/tomatodata.cgi of the com…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 8.8
CVE-2026-15543

A vulnerability was found in Tenda CH22 1.0.0.1. This impacts the function formCertListInfo of the file /goform/CertListInfo. The manipulation of the…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified HIGH 7.5
CVE-2026-14165

An Authorization Bypass Through User-Controlled Key vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15538

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the component AP…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 7.3
CVE-2026-15537

A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.p…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.3
CVE-2026-15536

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified HIGH 8.6
CVE-2026-12582

The Library Management System WordPress plugin before 3.5.8 does not sanitize and escape a user-supplied parameter before using it in a SQL statement…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 5.4
CVE-2026-12396

The WP Job Portal WordPress plugin before 2.5.5 does not perform capability or ownership checks before allowing job moderation actions, allowing aut…

No fix yet
Fix from $1,600 2026-07-13
Unclassified HIGH 7.1
CVE-2026-12275

The Tutor LMS WordPress plugin before 3.9.13 does not, in its Droip and Kirki page-builder integration, perform the enrollment, purchase, and privat…

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.5
CVE-2026-12274

The Tutor LMS WordPress plugin before 3.9.13 does not verify that the requesting user is allowed to edit a target post before overwriting it in one …

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 5.4
CVE-2026-12271

The Tutor LMS WordPress plugin before 3.9.13 does not verify ownership of the targeted quiz attempt before writing to it, allowing authenticated use…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 5.0
CVE-2026-12081

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.2 does not restrict the PHP classes allowed when unserializing …

Mitigation only
Fix from $1,600 2026-07-13
Unclassified CRITICAL 9.1
CVE-2026-11964

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified HIGH 8.1
CVE-2026-11963

The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives …

Mitigation only
Fix from $1,950 2026-07-13
Unclassified MEDIUM 6.1
CVE-2026-10551

The Breeze Cache WordPress plugin before 2.5.6 is vulnerable to unauthenticated Stored Cross-Site Scripting (XSS) due to a predictable replacement ha…

Mitigation only
Fix from $1,600 2026-07-13
Unclassified MEDIUM 5.3
CVE-2026-15530

A flaw has been found in WuzhiCMS up to 4.1.0. Affected by this vulnerability is the function config/listimage of the file /index.php?m=attachment&f=…

Mitigation only
Fix from $1,600 2026-07-13