Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-75840

ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped re…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-75838

DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detache…

No fix yet
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75837

Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75836

The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-75834

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). …

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.1
CVE-2026-75830

grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batc…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.1
CVE-2026-75829

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-75828

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75827

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-75107

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74906

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-74905

SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74904

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.6
CVE-2026-74902

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.7
CVE-2026-5224

Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-15585

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-75626

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject …

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-19608

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-19447

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO…

No fix yet
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-34884

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.1
CVE-2026-15371

Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-75091

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-15748

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.5
CVE-2026-11801

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75094

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75089

A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75088

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75087

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75086

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.…

No fix yet
Fix from $4,000 2026-08-18