Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2025-68075

Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2025-68074

Contributor Cross Site Scripting (XSS) in Image Carousel <= 1.0.0.41 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.5
CVE-2025-68064

Contributor Local File Inclusion in Goya Core < 1.0.9.4 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2025-68063

Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.8
CVE-2025-68052

Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.3
CVE-2025-66123

Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.3
CVE-2025-64637

Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.3
CVE-2025-64636

Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.4
CVE-2025-63041

Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-13426

The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API rou…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.3
CVE-2026-57915

It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users a…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 8.0
CVE-2026-40711

Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified CRITICAL 9.1
CVE-2025-64152

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.1
CVE-2025-55017

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57914

By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to d…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-57620

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows …

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57913

Johnson & Johnson Audit Tracking Management System (ATMS) before 2026-04-21 allows viewing of meeting minutes and transcripts.

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57912

Johnson & Johnson Campus Recruiting before 2025-10-31 allows viewing of data provided by recruited students, and notes entered about students by inte…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.8
CVE-2026-57473

A vulnerability exists in the netclient and factory services of Reolink Home Hub (versions prior to v3.3.0.456_26031911) due to the possibility of br…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified HIGH 7.1
CVE-2025-7958

A Code Injection vulnerability existed in Trellix Network Security CM and NX. A locally authenticated admin user can execute arbitrary code using the…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified MEDIUM 5.4
CVE-2026-6658

A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML expor…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified MEDIUM 6.5
CVE-2026-1869

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Buil…

Mitigation only
Fix from $1,600 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57881

An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57880

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57879

An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabili…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-57878

An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabi…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified HIGH 8.6
CVE-2026-57877

An unauthenticated format string vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57876

An unauthenticated out-of-bounds write vulnerability exists in onvif.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability …

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57875

An unauthenticated NULL pointer dereference vulnerability exists in the HTTP request parsing logic of multiple CGI components in GeoVision GV-LPC2011…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.5
CVE-2026-57874

An unauthenticated buffer overflow vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnera…

Mitigation only
Fix from $1,950 2026-06-26