Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-12410 Link following vulnerability in the Uninstaller component in CCleaner prior to 7.10.1464 on Windows allows a local, low-privileged attacker to escala… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-7529 The wiseCampaign – WooCommerce Conversions Made Easy plugin for WordPress is vulnerable to unauthorized modification and disclosure of data due to ev… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7456 The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `ajax_disconnect()` … No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-17506 The Independent Analytics plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 404 not_found_url tracking parameter in versions … No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-15979 The Content Egg – Affiliate Product Importer & Price Comparison plugin for WordPress is vulnerable to Arbitrary File Deletion via Path Traversal in v… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2025-70962 Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Control. The application contains hardcoded credentials in the RTSP authentication me… No fix yet Fix from $1,9502026-08-05 HIGH 7.6 CVE-2026-71294 Cotonti CMS's Comments plugin deserializes user-supplied data without restricting the classes that may be instantiated. In plugins/comments/controlle… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.2 CVE-2026-71293 Statamic CMS's user-augmentation resolver, AugmentedUser::get in src/Auth/AugmentedUser.php, contains an explicit case for the handle that returns th… No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-71292 Subrion CMS's admin grid sorting helper, _gridGetSorting in includes/classes/ia.base.controller.admin.php, whitelists the (ASC/DESC) request paramete… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71291 Bolt CMS renders content field values through Twig's full application-level Environment with no SandboxExtension registered anywhere in the codebase.… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-71289 The NASA-AMMOS Asynchronous Network Management System (ANMS) reference implementation's default docker-compose.yml publishes the amp-manager service'… No fix yet Fix from $2,3002026-08-05 HIGH 8.8 CVE-2026-71288 Koha's guided report builder (reports/guided_reports.pl) reads the CGI parameter and, for each value, a dynamically-named parameter, and concatenates… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71287 Cacti's sanitize_sql_column (lib/functions.php) sanitizes user-supplied ORDER BY column names using the regex . Because this allowlist retains letter… Mitigation only Fix from $1,9502026-08-05 MEDIUM 6.1 CVE-2026-71286 The render-template component of ember-dynamic-render-template (addon/components/render-template.js) passes its property directly into Ember/Glimmer'… No fix yet Fix from $1,6002026-08-05 HIGH 8.1 CVE-2026-71285 Uptime Kuma's Matomo analytics integration (server/analytics/matomo-analytics.js) injects the admin-configurable Matomo value as a bare, unquoted Jav… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-71284 Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), takes the first extracted tar member's fil… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71282 ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpolates the user-supplied tag KE… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-71281 Hugging Face peft's LoRA-GA and CorDA initialization modules (src/peft/tuners/lora/corda.py lines ~102 and ~163, and src/peft/tuners/lora/loraga.py l… No fix yet Fix from $1,9502026-08-05 HIGH 8.5 CVE-2026-71280 go-shiori's DownloadBookmark (internal/core/download.go) fetches a caller-supplied bookmark URL using a plain http.Client with no custom DialContext … No fix yet Fix from $1,9502026-08-05 HIGH 8.0 CVE-2026-71279 Zigbee2MQTT's ExternalJSExtension.getFilePath (lib/extension/externalJS.ts) joins a parameter received via an MQTT message (topic zigbee2mqtt/bridge/… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-71278 rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. Th… Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-71277 rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never … No fix yet Fix from $2,3002026-08-05 HIGH 7.1 CVE-2026-71276 Magistrala (formerly Mainflux)'s message-readers API reads a value from the HTTP query string (readers/api/http/transport.go) with no validation and … No fix yet Fix from $1,9502026-08-05 MEDIUM 5.4 CVE-2026-71275 OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(reques… No fix yet Fix from $1,6002026-08-05 HIGH 8.5 CVE-2026-71274 OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HT… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71273 OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the par… No fix yet Fix from $1,6002026-08-05 HIGH 8.5 CVE-2026-71272 Memos' webhook dispatch function safeDialContext (internal/webhook/webhook.go) resolves the target hostname via net.DefaultResolver.LookupHost and va… No fix yet Fix from $1,9502026-08-05 HIGH 8.5 CVE-2026-71271 Memos' webhook URL validation, isReservedIP (internal/webhook/validate.go), checks a candidate IP against a reservedCIDRs list that omits 0.0.0.0/8 a… No fix yet Fix from $1,9502026-08-05 HIGH 8.6 CVE-2026-71270 Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanitizer/SsrfProtectionService SS… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-71269 Node-RED's local-filesystem library storage module (getLibraryEntry and saveLibraryEntry in packages/node_modules/@node-red/runtime/lib/storage/local… No fix yet Fix from $1,9502026-08-05