Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-51119

An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-3251

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webremium Istanbul Web Design Mezunum Satiyorum…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-39244

adm-zip before 0.5.18 is vulnerable to denial of service via a crafted ZIP file with a manipulated uncompressed size header field. In zipEntry.js lin…

No fix yet
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-2398

Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue a…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.2
CVE-2026-1667

The SEO Plugin by Squirrly SEO plugin for WordPress is vulnerable to Arbitrary Post Creation and Stored Cross-Site Scripting in all versions up to, a…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15376

A vulnerability was found in Eleveo Call Recording Software 9.7.0. Affected is an unknown function of the file /callrec/statisticReportAction.do. The…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2025-70796

An unauthenticated path traversal vulnerability exists in the web management interface of WTI (Wireless Technology, Inc.) version 3.5.0.r 2024/05/24 …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-54149

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.0-lts, MaxKB tool import functionality in apps/tools/serializers/tool.py and MCP r…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15374

A flaw has been found in Eleveo Call Recording Software 9.7.0. This affects an unknown function of the file /callrec/roleAddAction.do of the componen…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15373

A vulnerability was detected in Eleveo Call Recording Software 9.7.0. The impacted element is an unknown function of the file /callrec/userAddAction.…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-15143

A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an arbitrary XML Sc…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-61455

Grav before 2.0.1 contains a decompression bomb vulnerability in ZipArchiver::extract() that lacks limits on uncompressed size, file count, and nesti…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-61450

Grav before 2.0.2 contains a Twig sandbox bypass that allows a page author (any admin.pages user, or anyone able to write to user/pages) to exfiltrat…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-61444

PraisonAI versions before 4.6.78 contain a code injection vulnerability in deploy/api.py where the agents_file parameter is directly interpolated int…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.8
CVE-2026-61437

PraisonAI (pip package praisonaiagents) before 1.6.78 contains an unsafe dynamic module loading vulnerability in AgentFlow._resolve_pydantic_class (s…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.8
CVE-2026-61434

PraisonAI versions before 4.6.78 contain an allowlist bypass vulnerability in shell command execution that allows attackers to execute restricted com…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.2
CVE-2026-60091

PraisonAI before 4.6.78 contains an unauthenticated server-side request forgery vulnerability in the Jobs API /api/v1/runs endpoint. The webhook_url …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-60086

PraisonAI before 4.6.78 contains a prompt injection defense bypass vulnerability where the injection defense only blocks threats classified as CRITIC…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-58661

n8n before 2.28.0 (and before 1.123.58 on the 1.x branch) contains a disk space exhaustion vulnerability in the data-table file upload endpoint. The …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-57994

phpMyFAQ before 4.1.5 applies inconsistent active=yes and publication-date filtering across its public FAQ API endpoints, allowing unauthenticated at…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-56765

Vikunja before 2.2.1 contains an authorization flaw where the LinkSharing.ReadAll endpoint exposes share hashes to users with read access, enabling p…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-56335

Capgo before 12.128.2 contains an authorization bypass vulnerability where write-scoped API keys can directly mutate protected channel configuration …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-56329

Capgo before 12.128.2 contains a cross-tenant preview namespace collision vulnerability caused by non-bijective decoding of double underscores to dot…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-56312

Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accounts before captcha valid…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-56309

Capgo before 12.128.2 fails to enforce plan/quota restrictions on the /files/upload/attachments endpoint, allowing plan-blocked apps to create public…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.3
CVE-2026-56305

Capgo before 12.128.2 contains an authentication bypass vulnerability in the password change endpoint that allows attackers to change user passwords …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-56279

Capgo before 12.128.2 contains an information disclosure vulnerability in the get_orgs_v7(userid) RPC function that remains publicly invokable despit…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.0
CVE-2026-56254

In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that download…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-38059

The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-38057

The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests …

Mitigation only
Fix from $1,950 2026-07-10