Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2024-58352

Landray OA contains an unauthenticated HQL injection vulnerability that allows unauthenticated attackers to query arbitrary Hibernate entity classes …

Mitigation only
Fix from $1,950 2026-07-02
Unclassified CRITICAL 9.8
CVE-2024-14037

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading …

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2022-50973

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified HIGH 7.8
CVE-2026-12168

An improper validation vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to escalate privileges to SYSTEM and …

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.8
CVE-2026-12167

The Minifilter communication port for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to access privileged driver functionalit…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.5
CVE-2026-12166

A NULL pointer dereference vulnerability for driver `GFAC_Sys_x64.sys` in Little Orbit GFAC allows a local attacker to cause a denial of service via …

Mitigation only
Fix from $1,600 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-4767

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-A…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-5524

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified MEDIUM 5.4
CVE-2026-4772

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Stored …

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 8.8
CVE-2026-57766

Unauthenticated Cross Site Request Forgery (CSRF) in WPIDE – File Manager & Code Editor <= 3.5.6 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57764

Contributor Cross Site Scripting (XSS) in Surbma | Yoast SEO Breadcrumb Shortcode <= 1.2 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57763

Contributor Cross Site Scripting (XSS) in Structured Content <= 1.7.0 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.9
CVE-2026-57762

Author Cross Site Scripting (XSS) in Simple URLs <= 151 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57761

Unauthenticated Cross Site Request Forgery (CSRF) in SEOWP <= 3.12.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-57760

Missing Authorization vulnerability in Sendcloud Sendcloud Shipping allows Exploiting Incorrectly Configured Access Control Security Levels. This is…

No fix yet
Fix from $1,600 2026-07-02
Unclassified HIGH 8.8
CVE-2026-57759

Unauthenticated Cross Site Request Forgery (CSRF) in ProfileGrid <= 5.9.9.7 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57758

Unauthenticated Cross Site Request Forgery (CSRF) in Permalink Manager for WooCommerce <= 1.0.8.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57757

Unauthenticated Cross Site Request Forgery (CSRF) in pCloud WP Backup <= 2.0.2 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57755

Contributor Cross Site Scripting (XSS) in Mosaic Gallery &#8211; Advanced Gallery <= 1.2.0 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57754

Contributor Cross Site Scripting (XSS) in Livemesh Addons for WPBakery Page Builder <= 3.9.4 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-57753

Unauthenticated Sensitive Data Exposure in Kit (formerly ConvertKit) for WooCommerce <= 2.1.5 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 8.5
CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

No fix yet
Fix from $1,950 2026-07-02
Unclassified HIGH 8.1
CVE-2026-57751

Unauthenticated Cross Site Request Forgery (CSRF) in Heateor Social Login <= 1.1.39 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.3
CVE-2026-57750

Unauthenticated Broken Access Control in ez Form Calculator Premium <= 2.14.1.2 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.5
CVE-2026-57749

Contributor Local File Inclusion in SportsPress Pro <= 2.7.29 versions.

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-57748

Contributor Local File Inclusion in Shopify <= 1.0.0 versions.

No fix yet
Fix from $1,950 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-57747

Unauthenticated Cross Site Request Forgery (CSRF) in Booked <= 3.0.0 versions.

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.1
CVE-2026-57746

Subscriber Broken Access Control in Booked <= 3.0.0 versions.

Mitigation only
Fix from $1,950 2026-07-02