Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.5
CVE-2026-14330

Multiple unbounded alloca() calls in the PulseAudio protocol server.

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-14324

RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.7
CVE-2026-13602

We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-12374

Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a throug…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.0
CVE-2026-13603

The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technolo…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified HIGH 8.1
CVE-2026-5120

A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from a…

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice MEDIUM 6.5
CVE-2026-53909

MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice MEDIUM 5.4
CVE-2026-53907

MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice MEDIUM 6.5
CVE-2026-53902

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u…

Mitigation only
Fix from $1,600 2026-07-01
Mycomplianceoffice HIGH 8.2
CVE-2026-53906

MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the …

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice HIGH 7.1
CVE-2026-53905

MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe…

Mitigation only
Fix from $1,950 2026-07-01
Mco HIGH 7.1
CVE-2026-53904

MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidate…

Mitigation only
Fix from $1,950 2026-07-01
Mycomplianceoffice HIGH 8.1
CVE-2026-53903

MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-13228

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ve…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 7.2
CVE-2026-12142

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter i…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-10095

The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.3
CVE-2026-27435

Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.5
CVE-2026-13454

The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and includ…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.1
CVE-2026-12754

The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 5.9
CVE-2026-56016

CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the ses…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 7.2
CVE-2026-50043

Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnera…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-13733

The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, a…

Mitigation only
Fix from $1,600 2026-07-01
Unclassified MEDIUM 6.4
CVE-2026-12732

The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, …

Mitigation only
Fix from $1,600 2026-07-01
Unclassified HIGH 8.7
CVE-2026-12577

DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability.

No fix yet
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-12576

DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability.

No fix yet
Fix from $1,950 2026-07-01
Unclassified HIGH 7.5
CVE-2026-12575

DVP80ES3 with  Improper Resource Shutdown or Release vulnerability.

No fix yet
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-12224

The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, …

Mitigation only
Fix from $1,950 2026-07-01
Unclassified HIGH 8.8
CVE-2026-12158

The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…

Mitigation only
Fix from $1,950 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-11387

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation v…

Mitigation only
Fix from $2,300 2026-07-01