Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-75829

grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-75828

Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-75827

Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-75107

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.9
CVE-2026-74907

Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74906

SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-74905

SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-74904

SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.6
CVE-2026-74902

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.7
CVE-2026-5224

Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.5
CVE-2026-15585

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-75626

SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject …

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-19608

A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-19447

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO…

No fix yet
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-34884

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.1
CVE-2026-15371

Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked …

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-75091

The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-15748

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.5
CVE-2026-11801

The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du…

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-75094

A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75089

A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75088

A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75087

A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin…

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75086

A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75080

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.3
CVE-2026-75079

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_sub…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.8
CVE-2026-67961

An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

No fix yet
Fix from $4,900 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-67919

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-42164

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.1
CVE-2026-42162

Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact…

No fix yet
Fix from $5,750 2026-08-17