Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.2
CVE-2026-29519

Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.0
CVE-2026-41880

R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 8.2
CVE-2026-41879

R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin cr…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.1
CVE-2026-41878

R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from th…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.1
CVE-2026-41877

R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the fil…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.7
CVE-2026-41876

R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-15378

A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery …

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-13710

The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-13247

The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-13010

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortco…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-11990

The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.1
CVE-2026-9838

The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-6802

The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-3907

The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-15104

The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-12924

The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.6
CVE-2025-11977

The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40454

Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40452

Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value dat…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.5
CVE-2026-40009

Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by re…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-40008

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qu…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40007

Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap re…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-40006

Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.1
CVE-2026-40005

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files a…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-28564

Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cache…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 7.5
CVE-2026-13347

The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrappe…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.5
CVE-2026-12685

The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.3
CVE-2026-12276

The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-12123

The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'v…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.8
CVE-2026-21057

Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory.

Mitigation only
Fix from $1,600 2026-07-10