Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.2
CVE-2026-58263

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. In versions prior to 4.12.28, the built-in clean-html sanitizer can be …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-55886

Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. Versions prior to 4.12.26 are vulnerable to Pro…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.3
CVE-2026-54756

Jodit Editor is a WYSIWYG editor with written in pure TypeScript file and image editing capabilities. In versions prior to 4.12.18, Jodit.configure(o…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.4
CVE-2026-54720

Silverstripe Framework is a PHP framework which powers the Silverstripe CMS. In versions prior to 6.2.2, the "Insert media from web" functionality in…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.8
CVE-2026-54074

Tina is a headless content management system. @tinacms/cli versions prior to 2.4.3 contain a Remote Code Execution vulnerability in the Forestry-to-T…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.1
CVE-2026-55153

mchange-commons-java is a Java library of shared utility classes used by mchange projects like the c3p0 connection pool. Prior to version 0.6.0, its …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.3
CVE-2026-58592

Ladybird contains a dangling-reference memory-safety flaw in its WebAssembly ESM-integration module loader. When a JavaScript function is imported in…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-58457

Shenzhen Aitemi M300 Wi-Fi Repeater (hardware model MT02) contains an unauthenticated OS command injection vulnerability that allows network-adjacent…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-54164

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions prior to 4.1.30, 4.2.26 and 4.3.12, the serializer's Abs…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-49858

API Platform Core is a system to create hypermedia-driven REST and GraphQL APIs. In versions from 2.6.0 prior to 4.1.29, 4.2.26, and 4.3.12, a missin…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.5
CVE-2026-55628

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` op…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-51947

An issue in Pivotal CRM 6.6.4.08 and systems using patch-ghi-15381-cwe-502-20251225.zip (fixed in Pivotal CRM 6.6.5.10 and Patch_CWE502_20260316.zip)…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-38142

An unauthenticated command injection vulnerability in the /goform/fast_setting_internet_set endpoint of Tenda AC18 v15.03.05.05 allows attackers to e…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.5
CVE-2026-13769

Overly permissive file permissions in AWS CLI before 1.44.78 (v1) and 2.34.29 (v2) on Unix-like systems where the umask has not been configured to re…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.3
CVE-2026-13760

OS command injection in the NodejsFunction Docker bundling pipeline (OsCommand helper) in AWS aws-cdk-lib on all platforms might allow a actor who co…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-57737

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Averta LTD Shortcodes and extra features for Ph…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.4
CVE-2026-57736

Insertion of Sensitive Information Into Sent Data vulnerability in HubSpot allows Retrieve Embedded Sensitive Data. This issue affects HubSpot: from…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.4
CVE-2026-57723

Cross-Site Request Forgery (CSRF) vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows Path Traversal. This issue affects VikBooki…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-57722

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ShortPixel Enable Media Replace allows Stored X…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-51946

SQL Injection vulnerability in GoAdminGroup GoAdmin (last release v1.2.26) allows a remote attacker to execute arbitrary code and obtain sensitive in…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-58454

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attacker…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-58453

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a hard-coded credentials vulnerability that allows network-adjacent atta…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified HIGH 8.8
CVE-2026-58452

JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain an OS command injection vulnerability that allows authenticated attacker…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-57721

Missing Authorization vulnerability in WP Reloaded ApplyOnline allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34117

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text_to_subtitles.php (line 19) without sanitization: exec(\"…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34116

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe.php (line 15) without sanitization: exec(\"php job…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34115

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34114

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34113

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jo…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34112

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01