Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-47831

Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attac…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.8
CVE-2026-47830

Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwr…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-12517

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-12516

The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 6.5
CVE-2026-12270

The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assista…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-11875

The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticate…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-11869

The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.5
CVE-2026-11571

The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leav…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 8.8
CVE-2026-5523

The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15138

A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_t…

Mitigation only
Fix from $1,600 2026-07-09
Dynamics 365 Customer Voice MEDIUM 6.1
CVE-2026-47646

Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15137

A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\Vie…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15135

A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.3
CVE-2026-15134

A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of …

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 6.3
CVE-2026-15105

A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp …

No fix yet
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.0
CVE-2026-5923

Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage.

No fix yet
Fix from $1,600 2026-07-08
Unclassified MEDIUM 5.9
CVE-2026-5922

The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage.

Mitigation only
Fix from $1,600 2026-07-08
Unclassified CRITICAL 9.8
CVE-2026-52200

An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint …

Mitigation only
Fix from $2,300 2026-07-08
Unclassified HIGH 7.5
CVE-2026-51535

In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop.

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.1
CVE-2026-35552

In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administ…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-10037

A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files ma…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.6
CVE-2026-60105

Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist chec…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.2
CVE-2026-59802

PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can cre…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.8
CVE-2026-36028

A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a fac…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified MEDIUM 6.8
CVE-2026-36027

An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and …

Mitigation only
Fix from $1,600 2026-07-08
Openshift Ai MEDIUM 6.5
CVE-2026-15154

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (R…

Mitigation only
Fix from $1,600 2026-07-08
Unclassified HIGH 8.7
CVE-2026-14891

HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 7.7
CVE-2026-14373

HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This …

Mitigation only
Fix from $1,950 2026-07-08
Unclassified HIGH 8.8
CVE-2026-53951

Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_setti…

Mitigation only
Fix from $1,950 2026-07-08
Unclassified MEDIUM 6.3
CVE-2026-15063

A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch servic…

Mitigation only
Fix from $1,600 2026-07-08