Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.9 CVE-2026-51385 An issue in safishamsi Open-Source GRAPHIFY v.0.3.2 through v0.4.29 allows a remote attacker to execute arbitrary code via the validate_url, safe_fet… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.9 CVE-2026-47134 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. The ECDSA private key used to sign the on-disk p… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.9 CVE-2026-47133 ClearanceKit intercepts file-system access events on macOS and enforces per-process access policies. Prior to version 5.0.10, each table in the on-di… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.1 CVE-2026-47128 nono is software that allows users to run AI agents in a zero-latency sandbox. Prior to version 0.55.0, the nono Landlock/seccomp policies allow acce… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-44510 Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver-sid… No fix yet Fix from $1,6002026-07-20 HIGH 7.3 CVE-2026-16324 A vulnerability was identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. The impacted element is an unknown function of the file /business/qna… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.4 CVE-2026-12900 The Spectra Gutenberg Blocks – Website Builder for the Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `uagb/i… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2024-51316 The Tenda TX9 V22.03.02.20 firmware has a denial of service vulnerability in the update_dev_name function of the file /goform/SetOnlineDevName No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2024-51315 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_425964 function of the file /goform/SetOnlineDevName No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2024-51314 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_424CE0 function of the file /goform/setMacFilterCfg. Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2024-51312 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EEE0 function of the file /goform/SetStaticRouteCfg. No fix yet Fix from $2,3002026-07-20 MEDIUM 5.3 CVE-2026-55219 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.5, the credit payment implementatio… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-53596 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the FreeScout helpdesk application does … No fix yet Fix from $1,6002026-07-20 CRITICAL 9.4 CVE-2026-53595 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the public endpoint `POST /user-setup/{h… No fix yet Fix from $2,3002026-07-20 HIGH 8.5 CVE-2026-47198 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the checkout component improperl… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-47130 NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Object Level Authorization (BOLA/IDOR)… No fix yet Fix from $1,9502026-07-20 HIGH 8.1 CVE-2026-47129 NextCRM is open-source customer relationship management (CRM) software. Versions prior to 0.12.0 have a Broken Access Control (BAC) vulnerability in … Mitigation only Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-44585 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the ticket creation endpoint acc… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-44583 Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the PayPal webhook endpoint /ext… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.3 CVE-2026-44509 Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, previous bug fix… No fix yet Fix from $1,6002026-07-20 HIGH 8.1 CVE-2026-44508 Rsync is a file-copying tool that uses a delta-transfer algorithm to synchronize remote and local files. In versions prior to 3.4.3, the receiver's … Mitigation only Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2024-51313 The Tenda TX9 V22.03.02.20 firmware has a stack overflow vulnerability in the sub_42EA38 function of the file /goform/SetVirtualServerCfg. No fix yet Fix from $2,3002026-07-20 CRITICAL 9.8 CVE-2024-51311 The Tenda TX9 V22.03.02.05 firmware has a stack overflow vulnerability in the sub_4418CC function of the file /goform/SetNetControlList. No fix yet Fix from $2,3002026-07-20 HIGH 8.1 CVE-2026-13381 VSee Clinic 7.1.26 and API 1.3.0 contain an Insecure Direct Object Reference (IDOR) vulnerability in the /v1.3.0/api/files endpoint. An authenticated… Clinic No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-13380 VSee Clinic 7.1.26 and VSee Clinic API 1.3.0 exposes cleartext SFTP credentials in the HTTP responses of three unauthenticated endpoints. The credent… Clinic No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-63766 GPT-SoVITS through 20250606v2pro contains an OS command injection vulnerability in webui.py where ASR, slice, denoise, and uvr5 functions interpolate… Mitigation only Fix from $2,3002026-07-20 HIGH 8.8 CVE-2026-53593 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.224, the denylist that neutralizes dangerous … No fix yet Fix from $1,9502026-07-20 HIGH 8.6 CVE-2026-53591 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.223, an unauthenticated attacker can inject m… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-64194 Net::DNS versions through 1.55 for Perl allow Denial of Service via deep DNS compression pointer chains. Net::DNS::DomainName::decode follows RFC 10… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-64193 Net::DNS versions through 1.55 for Perl allow remote execution injection via EDNS EXTENDED ERROR. Net::DNS::RR::OPT::EXTENDED_ERROR::_decompose pars… No fix yet Fix from $2,3002026-07-20