Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.1
CVE-2026-8306

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.1
CVE-2026-7380

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Contro…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified HIGH 7.5
CVE-2026-5799

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 7.5
CVE-2026-5730

Authorization bypass through User-Controlled key vulnerability in Idvlabs Software and Consulting Services Inc. Ontime allows Exploitation of Trusted…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 7.1
CVE-2026-57871

Relative path traversal vulnerability in MicroRealEstate file upload functionality allows attackers to potentially overwrite system files. This issu…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified MEDIUM 5.3
CVE-2026-57870

Broken object-level access control on the Template API in MicroRealEstate allows attackers to retrieve document templates used by other organizations…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified HIGH 7.1
CVE-2026-57869

Broken object-level access controls and the use of a deterministic pattern during random ID generation in MicroRealEstate allows attackers to access …

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 7.1
CVE-2026-57868

MicroRealEstate is affected by broken object-level access controls in PDF generator functionality. This issue affects MicroRealEstate: through 1.0.0…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 8.8
CVE-2026-57867

MicroRealEstate allows adversaries to bypass authentication due to a lack of token state management. This would permit adversaries targeting MicroRea…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified CRITICAL 9.0
CVE-2026-4375

The DoLeads Integrator WordPress plugin through 0.65, wp2epub WordPress plugin through 0.65 have been seen to be used to achieve RCE, once they are a…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-14345

The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Remote Code Execution in all ve…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified CRITICAL 9.8
CVE-2026-12375

The uncanny-automator-pro WordPress plugin before 7.3.0.6 was distributed with malicious code after the vendor's uncanny-automator-pro WordPress plug…

Mitigation only
Fix from $2,300 2026-07-07
Unclassified HIGH 8.7
CVE-2026-12277

The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced f…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified HIGH 8.8
CVE-2026-34158

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.469, the executeInDocker() he…

Mitigation only
Fix from $1,950 2026-07-07
Unclassified MEDIUM 6.4
CVE-2026-11328

The Exclusive Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the post title parameter in all versions up …

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.1
CVE-2026-53648

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.1, downloadable product files are stored using a determ…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 6.9
CVE-2026-53647

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.3 through 0.7.2, the Guest `serviceapikey/get_info` API endp…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.0
CVE-2024-56141

Minosoft is an open-source, multi-version Minecraft Java Edition client written in Kotlin. Starting in commit f1ae30e2b046a490026a8413b075685deb79512…

Mitigation only
Fix from $1,600 2026-07-07
Unclassified MEDIUM 5.3
CVE-2026-53642

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when the "Require Email Confirmation" setti…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified HIGH 7.7
CVE-2026-53646

FOSSBilling is a free, open-source billing and client management system. In versions 0.5.6 through 0.7.2, when a `ClientPasswordReset` record already…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.5
CVE-2026-53645

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow a low-privileged staff account to grant arbitr…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.6
CVE-2026-53644

FOSSBilling is a free, open-source billing and client management system. Versions 0.5.3 through 0.7.2 allow authenticated clients to both read and re…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.7
CVE-2026-53643

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 allow low-privileged staff accounts to perform unaut…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.9
CVE-2026-43927

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, a race condition in the cart checkout flow allows an…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.9
CVE-2026-43925

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in …

Mitigation only
Fix from $1,600 2026-07-06
Unclassified HIGH 8.9
CVE-2026-43921

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.10 through 0.7.2 have a PHP code injection vulnerability in FOS…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.7
CVE-2026-43918

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, when a client or staff/admin account is suspended or…

No fix yet
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.1
CVE-2026-59711

showdown contains a cross-site scripting vulnerability in metadata title handling that allows attackers to inject arbitrary HTML and JavaScript. When…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified HIGH 7.5
CVE-2026-55727

A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthen…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified MEDIUM 6.9
CVE-2026-33734

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have a SQL injection vulnerability in the `Mass…

Mitigation only
Fix from $1,600 2026-07-06