Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-67325 GitPython before 3.1.51 contains an incomplete command injection blocklist that fails to account for git's long-option prefix abbreviation feature. A… No fix yet Fix from $1,9502026-08-01 CRITICAL 9.8 CVE-2026-67324 GitPython 3.1.50 fails to recognize joined short-option forms such as -u<value> (the short form of --upload-pack=<value>) when enforcing its default … No fix yet Fix from $2,3002026-08-01 HIGH 8.4 CVE-2026-67323 GitPython before 3.1.51 fails to guard against dangerous Git options passed as keyword arguments in Repo.archive() and git.ls_remote(), allowing comm… No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-67322 GitPython before 3.1.52 is vulnerable to environment-variable exfiltration in Repo.clone_from(). The caller-supplied remote URL is passed through Git… No fix yet Fix from $1,9502026-08-01 MEDIUM 6.9 CVE-2026-67321 axios versions 0.31.1 before 0.33.0 and 1.15.1 before 1.18.0 contain an incomplete depth-limit bypass in toFormData.js when serializing objects with … No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67319 axios before 0.33.0 (and 1.x before 1.18.0) can consume inherited properties from nested request option objects when the JavaScript process's Object.… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67318 axios versions >=1.13.0 (Node.js HTTP adapter) fail to enforce the configured maxBodyLength limit on streamed request bodies when requests are sent w… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67317 axios versions 1.7.0 before 1.18.0 fail to enforce maxBodyLength for WHATWG ReadableStream request bodies in the fetch adapter when Content-Length ca… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67316 axios is vulnerable to read-side prototype-pollution gadgets that can alter request construction when Object.prototype has already been polluted by a… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.9 CVE-2026-67315 axios versions 0.31.0 before 0.33.0 and 1.15.0 before 1.18.0 fail to recognize 0.0.0.0 as a loopback address in shouldBypassProxy.js, allowing reques… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67314 axios versions >=1.15.2 and <1.18.0 contain prototype-pollution read-side gadgets in Basic auth subfield handling (lib/adapters/http.js and lib/helpe… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67313 axios versions 0.28.0 and later contain uncontrolled recursion in formDataToJSON when processing FormData field names with deeply nested bracket segm… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.3 CVE-2026-67312 axios versions from 0.28.0 before 0.33.0 and from 1.0.0 before 1.18.0 contain uncontrolled recursion in formDataToJSON (exposed as axios.formToJSON()… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.8 CVE-2026-67311 Budibase before 3.38.1 contains a server-side request forgery vulnerability in the REST datasource integration that fails to validate HTTP redirects … No fix yet Fix from $1,6002026-08-01 MEDIUM 5.4 CVE-2026-67310 OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in the setAssetLinks endpoint of … No fix yet Fix from $1,6002026-08-01 CRITICAL 9.3 CVE-2026-67308 Wazuh workflows before 44bf114 contain a shell injection vulnerability in GitHub Actions that allows attackers to execute arbitrary commands by submi… No fix yet Fix from $2,3002026-08-01 CRITICAL 9.4 CVE-2026-67305 FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONT… No fix yet Fix from $2,3002026-08-01 HIGH 7.5 CVE-2026-67297 FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body()… No fix yet Fix from $1,9502026-08-01 HIGH 7.5 CVE-2026-67296 FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length b… No fix yet Fix from $1,9502026-08-01 HIGH 7.1 CVE-2025-71403 better-auth versions before 1.1.20 contain a bypass vulnerability in trustedOrigins validation logic affecting absolute URLs and wildcard domains. At… No fix yet Fix from $1,9502026-08-01 MEDIUM 6.5 CVE-2026-6453 The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. This is due to insufficient inpu… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.4 CVE-2026-18435 The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'toggleIcon' Blo… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.1 CVE-2026-18344 The Wp Responsive Thumbnail Slider plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'id' parameter in versions up to, and… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.4 CVE-2026-18062 The Kadence Blocks — Page Builder Toolkit for Gutenberg Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Identity Block I… No fix yet Fix from $1,6002026-08-01 MEDIUM 5.3 CVE-2026-18059 The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, … No fix yet Fix from $1,6002026-08-01 MEDIUM 6.5 CVE-2026-17580 The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elementor, Divi, Beaver… plugin f… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.1 CVE-2026-17571 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Reflected Cross-Site… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.4 CVE-2026-16685 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'icon' Shortcode Attribute in all versions up to, and incl… No fix yet Fix from $1,6002026-08-01 MEDIUM 6.4 CVE-2026-16684 The Easy Property Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'facebook' User Contact Method in all versions up to… No fix yet Fix from $1,6002026-08-01 HIGH 8.8 CVE-2026-16635 The Pronamic Pay plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.1.0 This is due to the `maybe_up… Mitigation only Fix from $1,9502026-08-01