Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.6 CVE-2026-58047 HTTP Smuggling in cPanel allows potential leak of credentials. No fix yet Fix from $1,6002026-07-31 MEDIUM 5.9 CVE-2026-67607 LightFTP 2.3.1 contains a residual race condition vulnerability (an incomplete fix for CVE-2024-11144) in the worker_thread_cleanup() function of ftp… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-56568 HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays ra… Icontrol No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-56571 HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, databa… Icontrol No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-56570 HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresse… Icontrol No fix yet Fix from $1,6002026-07-31 MEDIUM 5.1 CVE-2026-56567 HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to… No fix yet Fix from $1,6002026-07-31 HIGH 8.2 CVE-2026-18141 A flaw was found in aap-gateway, a component of Ansible Automation Platform's Event-Driven Ansible (EDA). An unauthenticated remote attacker can bypa… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-16504 Deployment of the VPS.org one-click Zulip template deploys a hardcoded application signing key, a default database password ("zulip"), and DISABLE_HT… Mitigation only Fix from $2,3002026-07-31 CRITICAL 9.1 CVE-2026-16503 Deployment of the VPS.org one-click Supabase template deploys a PostgreSQL instance that is published on all interfaces (0.0.0.0:5432) with a default… No fix yet Fix from $2,3002026-07-31 HIGH 7.5 CVE-2026-18446 fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forward slash to recognize a URI authority, so a reference that uses a backslash ba… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-28145 Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User State. This issue affects Ma… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-18358 A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterprise Linux. When the daemon is running in system mode with RDP enabled, the inco… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.8 CVE-2026-17561 Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign… No fix yet Fix from $2,3002026-07-31 MEDIUM 5.3 CVE-2026-15227 Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and 2.2.0 (EOL) allows an authenticated user lacking the "Edit foreign Reports" per… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.1 CVE-2026-46594 A reflected cross-site scripting (XSS) vulnerability has been identified in the PHP Jabbers - PHP Poll Script. A malicious attacker can craft a speci… No fix yet Fix from $1,6002026-07-31 HIGH 8.6 CVE-2026-46593 A SQL injection vulnerability has been identified in the PHP Jabbers - PHP Poll Script. Improper neutralization of input provided by user to pjAdminP… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.9 CVE-2025-67651 A Cross-Site Request Forgery (CSRF) vulnerability has been identified in multiple PHP Jabbers scripts. The lack of CSRF tokens or appropriate SameSit… No fix yet Fix from $1,6002026-07-31 HIGH 8.6 CVE-2025-67650 An authenticated SQL injection vulnerability has been identified in multiple PHP Jabbers scripts. Improper neutralization of input provided by an aut… No fix yet Fix from $1,9502026-07-31 CRITICAL 9.3 CVE-2025-67649 A SQL injection vulnerability has been identified in PHP Jabbers - Car Rental Script . Improper neutralization of input provided by user into paramet… No fix yet Fix from $2,3002026-07-31 MEDIUM 5.3 CVE-2026-17567 The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulnerable to Insecure Direct Obje… No fix yet Fix from $1,6002026-07-31 HIGH 7.2 CVE-2026-16843 Some Hikvision Networking Products are vulnerable to authenticated command execution due to insufficient input validation. Attackers with valid crede… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-18437 The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access due to a missing capability c… No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-18436 The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the campaign revision-restore RES… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-15722 A stack buffer overflow flaw was found in 389 Directory Server (389-ds-base). The get_ruvelement_from_berval() function in repl5_ruv.c copies digit c… Directory Server No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-11770 A flaw was found in 389 Directory Server. An unauthenticated remote attacker can inject LDAP search filters into the CleanAllRUV replication status-c… Directory Server No fix yet Fix from $1,9502026-07-31 HIGH 8.5 CVE-2026-10079 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). When processing Kubernetes Deployments, ACS replaces deployment identit… No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-65313 A provisioning script used when installing HIPASE-250 (formerly 250 SCALA) engineering workstations sets a fixed, hard-coded x11vnc password. Because… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.3 CVE-2026-65311 The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's … No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any a… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.4 CVE-2026-18218 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe… Build Of Keycloak No fix yet Fix from $1,6002026-07-31