Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.1
CVE-2026-35096

KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can cra…

Mitigation only
Fix from $1,600 2026-06-30
Firefox CRITICAL 9.8
CVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified MEDIUM 5.9
CVE-2026-14178

openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 seqscan + s…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 6.1
CVE-2026-8403

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer In…

Mitigation only
Fix from $1,600 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-4629

A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role …

No fix yet
Fix from $1,600 2026-06-30
Build Of Keycloak MEDIUM 6.5
CVE-2026-12388

A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is …

Mitigation only
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-8402

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer In…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified MEDIUM 5.9
CVE-2026-57082

Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream En…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 7.5
CVE-2026-57081

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested li…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.5
CVE-2026-57080

Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framin…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.3
CVE-2026-57079

Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorr…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 5.9
CVE-2026-53692

Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically broken algorithm and lacks…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified HIGH 8.6
CVE-2026-53691

An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-53690

An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The ap…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-14162

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 7.5
CVE-2026-14161

Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a…

Mitigation only
Fix from $1,950 2026-06-30
Activemq HIGH 7.5
CVE-2026-50750

Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-9711

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 7.2
CVE-2026-8141

The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all v…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified MEDIUM 5.1
CVE-2026-6954

Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or i…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified MEDIUM 5.1
CVE-2026-6953

HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML …

Mitigation only
Fix from $1,600 2026-06-30
Enterprise Linux MEDIUM 6.4
CVE-2026-12610

A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory …

Mitigation only
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12076

Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to e…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified HIGH 7.0
CVE-2026-10763

PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server.

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 8.4
CVE-2026-12578

The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code.

No fix yet
Fix from $1,950 2026-06-30
Unclassified HIGH 7.2
CVE-2026-56808

DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified HIGH 7.8
CVE-2026-56137

RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file…

Mitigation only
Fix from $1,950 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12819

Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified MEDIUM 6.1
CVE-2026-56809

Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerabil…

Mitigation only
Fix from $1,600 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12818

Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP …

Mitigation only
Fix from $2,300 2026-06-30