Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-34111

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"php…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php …

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34109

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/sp…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34107

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34105

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, ext…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34104

Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34103

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extensio…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34102

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where i…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34101

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extensio…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34100

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, t…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = …

Mitigation only
Fix from $2,300 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-27409

Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This iss…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.5
CVE-2026-20191

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  …

Mitigation only
Fix from $1,950 2026-07-01
Mediawiki HIGH 7.5
CVE-2026-58036

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-24270

NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lea…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified HIGH 8.5
CVE-2026-24260

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful ex…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.0
CVE-2025-23351

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.0
CVE-2025-23350

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write…

Mitigation only
Fix from $2,300 2026-07-01
Fatfs HIGH 7.6
CVE-2026-6688

FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling. With LFN enabled, fno.fname …

No fix yet
Fix from $1,950 2026-07-01
Fatfs HIGH 7.6
CVE-2026-6687

FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec ma…

No fix yet
Fix from $1,950 2026-07-01
Fatfs MEDIUM 6.1
CVE-2026-6685

FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read() / f_write() (fp->sect - sect < cc) during interle…

No fix yet
Fix from $1,600 2026-07-01
Fatfs HIGH 7.6
CVE-2026-6682

In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlle…

No fix yet
Fix from $1,950 2026-07-01
Unclassified MEDIUM 5.4
CVE-2026-6283

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-5220

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 8.7
CVE-2026-58399

@acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication byp…

Mitigation only
Fix from $1,950 2026-07-01
Mediawiki MEDIUM 5.4
CVE-2026-58031

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 8.2
CVE-2026-2891

The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data.…

Mitigation only
Fix from $1,950 2026-07-01