Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-1771 The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all version… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-15370 A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack… Hardened Images No fix yet Fix from $1,9502026-07-21 MEDIUM 5.3 CVE-2026-8593 Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users … No fix yet Fix from $1,6002026-07-21 HIGH 7.1 CVE-2026-3183 Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass. No fix yet Fix from $1,9502026-07-21 HIGH 7.5 CVE-2026-8082 The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce or… No fix yet Fix from $1,9502026-07-21 MEDIUM 5.4 CVE-2026-14184 The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, al… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.5 CVE-2026-13694 The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.9 CVE-2026-13693 The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a no… No fix yet Fix from $1,6002026-07-21 HIGH 8.8 CVE-2026-11767 The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputti… Mitigation only Fix from $1,9502026-07-21 MEDIUM 6.8 CVE-2026-15927 A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an exte… No fix yet Fix from $1,6002026-07-21 MEDIUM 5.8 CVE-2026-15811 A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe s… No fix yet Fix from $1,6002026-07-21 CRITICAL 9.8 CVE-2026-13439 The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, a… No fix yet Fix from $2,3002026-07-21 MEDIUM 6.4 CVE-2026-15156 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Read… No fix yet Fix from $1,6002026-07-21 MEDIUM 6.8 CVE-2026-59776 Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, in… No fix yet Fix from $1,6002026-07-21 HIGH 7.2 CVE-2026-6952 A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5… No fix yet Fix from $1,9502026-07-21 MEDIUM 6.3 CVE-2026-16334 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder… No fix yet Fix from $1,6002026-07-21 HIGH 7.3 CVE-2026-16332 A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16331 A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16330 A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16329 A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation… No fix yet Fix from $1,9502026-07-21 HIGH 7.3 CVE-2026-16327 A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a … No fix yet Fix from $1,9502026-07-21 CRITICAL 9.8 CVE-2026-64625 AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command… No fix yet Fix from $2,3002026-07-20 MEDIUM 5.6 CVE-2026-57852 Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured … No fix yet Fix from $1,6002026-07-20 HIGH 8.2 CVE-2026-57495 AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to v… Mitigation only Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-57494 AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated Agent… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-55550 NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli… No fix yet Fix from $1,9502026-07-20 HIGH 7.6 CVE-2026-55544 NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-52656 An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary … No fix yet Fix from $2,3002026-07-20 HIGH 7.5 CVE-2026-51031 FlareSolverr before version 3.4.7 contains a server-side request forgery (SSRF) vulnerability in the /v1 API endpoint. This allows a remote attacker … No fix yet Fix from $1,9502026-07-20 MEDIUM 6.1 CVE-2026-51025 Cross Site Scripting vulnerability in fuint Member Marketing System <=v1.0 allows a remote attacker to execute arbitrary code via the ClientMessageCo… No fix yet Fix from $1,6002026-07-20