Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-63771 Adminer before 5.4.3 contains a cookie injection vulnerability that allows attackers to manipulate cookie attributes by injecting arbitrary values th… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-63108 Roo Code through 3.54.0 contains a command injection vulnerability in the auto-approve execute feature that allows attackers to bypass allowlist/deny… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.1 CVE-2026-62414 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK does not properly apply ac… Mitigation only Fix from $2,3002026-07-20 MEDIUM 6.1 CVE-2026-61901 Joomla Extension - hikashop.com - Open redirect in Hikashop < 6.5.2 - The Joomla extension Hikashop is vulnerable to an open redirect. No fix yet Fix from $1,6002026-07-20 HIGH 7.7 CVE-2026-63107 LimeSurvey through 6.17.10 and 7.0.4 contains a server-side request forgery vulnerability in the REST API survey template endpoint that allows authen… No fix yet Fix from $1,9502026-07-20 CRITICAL 10.0 CVE-2026-61900 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable… Mitigation only Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-61425 Joomla Extension - balbooa.com - Authentication bypass in Gridbox < 1.6.0 - The Joomla extension Gridbox is vulnerable an authenticated bypass, poten… No fix yet Fix from $2,3002026-07-20 CRITICAL 10.0 CVE-2026-61424 Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vuln… No fix yet Fix from $2,3002026-07-20 CRITICAL 9.4 CVE-2026-60034 Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS … No fix yet Fix from $2,3002026-07-20 MEDIUM 5.1 CVE-2026-60033 Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulne… No fix yet Fix from $1,6002026-07-20 CRITICAL 9.4 CVE-2026-60032 Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authentic… No fix yet Fix from $2,3002026-07-20 MEDIUM 6.9 CVE-2026-60031 Joomla Extension - themexpert.com - Information disclosure in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable to… No fix yet Fix from $1,6002026-07-20 HIGH 8.7 CVE-2026-60030 Joomla Extension - themexpert.com - Broken Access Control for media management in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder … No fix yet Fix from $1,9502026-07-20 MEDIUM 5.1 CVE-2026-60029 Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable … No fix yet Fix from $1,6002026-07-20 HIGH 8.6 CVE-2026-60028 Joomla Extension - themexpert.com - Authenticated stored XSS in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vulnerable … No fix yet Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-60027 Joomla Extension - themexpert.com - Unauthenticated path traversal / file read in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder … No fix yet Fix from $1,9502026-07-20 HIGH 8.9 CVE-2026-60026 Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1 - The Joomla extension Quix Page Builder Pro is vul… No fix yet Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-8170 The mv, cp, and rm file utilities exposed within the ExtremeXOS (EXOS) shell environment fail to safely canonicalize paths and follow symbolic links … No fix yet Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-8169 ExtremeXOS (EXOS) uses a challenge-response mechanism to authorize access to the privileged debug-mode function. The challenge value is generated usi… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-64612 A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery hand… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.5 CVE-2026-45295 FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.219, the open tracking endpoint `GET /thread/… No fix yet Fix from $1,6002026-07-20 CRITICAL 9.3 CVE-2026-39878 Chamilo LMS versions 1.11.38 and earlier contain a stored cross-site scripting vulnerability in the user registration form that allows any unauthenti… Mitigation only Fix from $2,3002026-07-20 HIGH 7.5 CVE-2026-34239 Chamilo version 1.11.40 and earlier are vulnerable to authenticated remote code execution in the main/inc/ajax/lang.ajax.php path. This endpoint is p… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.1 CVE-2026-26483 Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scripting (XSS) vulnerability in the template management functionality. The applicat… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-50743 A CSRF vulnerability exists in the `zone-include.php` script in Revive Adserver 6.0.7. Linking and unlinking banners or campaigns to zones could be t… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-47276 In nanomq versions 0.24.11 and earlier, a NULL pointer dereference in `properties_parse()` allows an authenticated attacker to crash the NanoMQ broke… No fix yet Fix from $1,6002026-07-20 HIGH 8.6 CVE-2026-40187 In egroupware version 26.0 and earlier, an authenticated administrator can achieve OS-level Remote Code Execution (RCE) by uploading a malicious eTem… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-39879 Due to a missing sanitization call in [`afsql_dd_run_query`](https://github.com/syslog-ng/syslog-ng/blob/649e6e18e3459fb4467000a88dfb12fa97f9719c/mod… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-39385 Frappe LMS is an open source learning management system. In version 2.51.0 and earlier, a user could bypass payment validation for courses by using u… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.5 CVE-2026-35217 NanoMQ contains a protocol-semantics flaw in its MQTT v5 `SUBSCRIBE` handling: if a subscription entry is missing the final 1-byte `Subscription Opti… No fix yet Fix from $1,6002026-07-20