Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-66803 Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. Azure Cosmos Db No fix yet Fix from $2,3002026-07-30 CRITICAL 9.3 CVE-2026-66418 OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.1 CVE-2026-52539 Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-35847 An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69931 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69947 SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69941 SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69938 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69937 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69936 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69935 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69934 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69933 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69930 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. No fix yet Fix from $2,3002026-07-30 MEDIUM 6.1 CVE-2025-65342 code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2025-65341 Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. No fix yet Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2025-65336 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67594 Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67208 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by … No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-67207 Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users… Mitigation only Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-67206 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-66756 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a… Tika No fix yet Fix from $2,3002026-07-30 MEDIUM 6.6 CVE-2026-65835 Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.8 CVE-2026-65834 Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex a… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2025-51684 CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessa… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-61536 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-51272 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-12118 IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary code on the system due to the d… Webmethods Integration No fix yet Fix from $2,3002026-07-30 MEDIUM 5.5 CVE-2025-36374 IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privileged user could exploit this v… No fix yet Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-62663 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.4, all four media filters (image, audio, video, doc… No fix yet Fix from $1,9502026-07-30