Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2025-67405 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_password.php via the parameter new_password. No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2025-67404 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in save_stud.php via the parameters fname, lname, and student_cla… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2025-67403 Sourcecodester CASAP Automated Enrollment System 1.0 is vulnerable to SQL Injection in update_class.php via the parameter class_name. No fix yet Fix from $2,3002026-07-29 HIGH 7.5 CVE-2026-50782 Jinher OA C6 contains an XML External Entity (XXE) injection vulnerability in the /c6/JHSoft.Web.HrmAttendance/sp_manager_getUserlist.aspx/GetXmlHttp… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.8 CVE-2026-13309 Autel MaxiCharger AC Elite Home NFC Stack-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present … No fix yet Fix from $1,6002026-07-29 HIGH 8.1 CVE-2026-13308 Autel MaxiCharger AC Elite Home WebSockets Integer Underflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execu… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.8 CVE-2026-13307 Autel MaxiCharger AC Elite Home USB Heap-based Buffer Overflow Arbitrary Code Execution Vulnerability. This vulnerability allows physically present a… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.4 CVE-2026-13305 Autel MaxiCharger AC Elite Home Software Update Improper Verification of Cryptographic Signature Arbitrary Code Execution Vulnerability. This vulnera… No fix yet Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2025-65340 kishan0725 Hospital Management System 4.0 is vulnerable to SQL Injection in /betweendates-detailsreports.php. No fix yet Fix from $2,3002026-07-29 MEDIUM 6.1 CVE-2025-65337 Sourcecodester Fantastic Blog CMS 1.0 is vulnerable to Cross Site Scripting (XSS) in pageEditMember.php via the address field. No fix yet Fix from $1,6002026-07-29 HIGH 7.8 CVE-2026-6102 MSI Center NTIOLib_X64 Origin Validation Error Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privil… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-5492 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-5491 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,9502026-07-29 HIGH 8.8 CVE-2026-5490 DriveLock SQL Injection Privilege Escalation Vulnerability. This vulnerability allows remote attackers to escalate privileges on affected installatio… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-5489 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-5487 DriveLock Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on a… No fix yet Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-5057 ATEN Unizon RpcProvider Missing Authentication Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-serv… No fix yet Fix from $1,9502026-07-29 HIGH 7.8 CVE-2026-5056 GStreamer qtdemux Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary co… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.4 CVE-2026-18266 Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affe… No fix yet Fix from $1,6002026-07-29 HIGH 7.8 CVE-2026-13268 G DATA Total Security Backup Service Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate p… No fix yet Fix from $1,9502026-07-29 HIGH 7.2 CVE-2026-12357 Heimdall Data Database Proxy generateFileContent CRLF Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to ex… No fix yet Fix from $1,9502026-07-29 HIGH 8.6 CVE-2026-16328 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing a connected client to overrid… No fix yet Fix from $1,9502026-07-29 CRITICAL 10.0 CVE-2026-16326 In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not properly isolate session state in stateless mode, which may allow one client's Consul authen… No fix yet Fix from $2,3002026-07-29 HIGH 8.7 CVE-2026-12935 The TL-WR940N v6 router contains a vulnerability in its RTSP connection tracking module that can lead to a stack-based buffer overflow. The issue occ… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-41939 Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows u… Mitigation only Fix from $2,3002026-07-29 HIGH 7.0 CVE-2026-40272 Improper Input Validation in the decode() function of the traceparser library could allow an attacker with a corrupted kernel trace event log (.kev) … No fix yet Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-8339 A SQL injection vulnerability exists in the Coverity Connect SOAP API for versions between 2024.6.0 and 2026.3.0 (inclusive). A malicious, authentica… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.2 CVE-2026-8338 A Spring Security authentication and authorization bypass exists in Coverity Connect versions between 2023.6.0 and 2026.3.0. An unauthenticated malic… No fix yet Fix from $2,3002026-07-29 HIGH 7.8 CVE-2026-64560 In the Linux kernel, the following vulnerability has been resolved: posix-cpu-timers: Prevent UAF caused by non-leader exec() race Wongi and Jungwo… No fix yet Fix from $1,9502026-07-29 HIGH 7.8 CVE-2026-64559 In the Linux kernel, the following vulnerability has been resolved: s390/pkey: Check length in PKEY_VERIFYPROTK ioctl Explicitly check the buffer l… No fix yet Fix from $1,9502026-07-29