Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.2
CVE-2026-42341

FOSSBilling is a free, open-source billing and client management system. Versions 0.6.0 through 0.7.2 have an unauthenticated payment bypass vulnerab…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified HIGH 7.7
CVE-2026-42331

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Guest API invoice/update endpoint is missing an …

Mitigation only
Fix from $1,950 2026-07-06
Cologne Firmware HIGH 7.0
CVE-2026-25271

Memory Corruption when processing asynchronous input parameters due to improper handling of modified values between check and use.

Mitigation only
Fix from $1,950 2026-07-06
Wsa8835 Firmware HIGH 8.8
CVE-2026-25268

Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.

Mitigation only
Fix from $1,950 2026-07-06
Aqt1000 Firmware HIGH 7.8
CVE-2026-21379

Memory Corruption when allocating memory with sizes that exceed the maximum allowed value.

No fix yet
Fix from $1,950 2026-07-06
Unclassified HIGH 8.1
CVE-2026-14471

Improper Neutralization of Special Elements in the metrics-service retention policy management component in Amazon mcp-gateway-registry before 1.0.13…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.7
CVE-2026-14468

HashiCorp Terraform Enterprise contained an issue in its version control system (VCS) ingestion of registry modules that did not correctly enforce th…

Mitigation only
Fix from $1,950 2026-07-06
Fastconnect 6900 Firmware HIGH 7.1
CVE-2026-21383

Cryptographic Issue when using a static initialization vector for AES-GCM key wrapping, which requires a unique value for each call to ensure securit…

Mitigation only
Fix from $1,950 2026-07-06
Enterprise Linux MEDIUM 5.5
CVE-2026-59089

A flaw was found in GIMP. The PlayStation TIM loader, responsible for handling PlayStation image files, incorrectly calculates the size of the Color …

No fix yet
Fix from $1,600 2026-07-06
Unclassified MEDIUM 6.5
CVE-2026-14898

The OpenAI Codex desktop app for macOS rendered remote images from Markdown in model responses. An attacker who could place an indirect prompt inject…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified CRITICAL 9.8
CVE-2026-11405

The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified HIGH 7.5
CVE-2026-13753

A missing authorization vulnerability exists in the embedded webserver of HP Deskjet 2800 Series Printers running firmware version <=TBP1CN2612AR. An…

No fix yet
Fix from $1,950 2026-07-06
Unclassified CRITICAL 9.9
CVE-2026-48614

An improper authorization vulnerability in the Plesk XML API allows an authenticated user to inject arbitrary configuration directives, resulting in …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified MEDIUM 6.4
CVE-2026-12154

The Reviews Widgets for Google, Yelp & TripAdvisor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'page_id' shortcode attr…

Mitigation only
Fix from $1,600 2026-07-06
Coldfusion CRITICAL 10.0
CVE-2026-48316

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut…

Mitigation only
Fix from $2,300 2026-07-06
Opennlp HIGH 7.3
CVE-2026-43825EPSS 9%

Untrusted Java Deserialization in Apache OpenNLP SvmDoccatModel Versions Affected:   before 3.0.0-M4 (libsvm document categorization module; introdu…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.2
CVE-2025-53831

DrawIO for ownCloud is an application for using DrawIO with the file storage, synchronization, and sharing application ownCloud Classic. In DrawIO fo…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified CRITICAL 9.1
CVE-2026-5268

An authentication bypass vulnerability exists in the default SFTP server component utilized across the Ciena products listed. This vulnerability allo…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified MEDIUM 5.0
CVE-2026-59152

LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to 0.8.18, an attacker who can send an HTTP request to a serve…

Mitigation only
Fix from $1,600 2026-07-06
Unclassified CRITICAL 9.1
CVE-2025-53830

Anti-Virus for ownCloud is an anti-virus application for file storage, synchronization, and sharing application ownCloud. Versions of Anti-Virus for …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified HIGH 8.0
CVE-2025-53829

ownCloud is a file storage, synchronization, and sharing application. In ownCloud 10 prior to version 10.15.3, an attacker with administrative privil…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 8.5
CVE-2025-53828

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing application ownCloud Classic. In S…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified CRITICAL 9.1
CVE-2025-53827

ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified MEDIUM 6.0
CVE-2026-7185

A validation vulnerability has been identified in certain web features related to file management or upload in several products of the TAO 2.0 suite.…

Mitigation only
Fix from $1,600 2026-07-06
Enterprise Linux HIGH 7.8
CVE-2026-58380

A flaw was found in GIMP's PNM file format parser. When parsing a specially crafted PNM file, the pnmscanner_gettoken() function writes a null termin…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.7
CVE-2026-6901

Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.4
CVE-2026-6900

Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.

Mitigation only
Fix from $1,950 2026-07-06
Unclassified CRITICAL 9.3
CVE-2026-12686

An authenticated user could manipulate a company ID parameter in a POST request to the backend to gain unauthorised access to other companies hosted …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified HIGH 7.7
CVE-2026-9165

A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authe…

Mitigation only
Fix from $1,950 2026-07-06
Unclassified HIGH 7.0
CVE-2026-44934

A information disclosure when DEBUG loglevel is set in SUSE Rancher AI Agent 1.0 before 1.0.2 could leak API keys or LLM response text with potential…

Mitigation only
Fix from $1,950 2026-07-06