Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-35048 The Piwigo installer in versions 16.3.0 and earlier accepts POST parameters for database configuration and writes them directly into a PHP configurat… Mitigation only Fix from $2,3002026-07-20 HIGH 7.3 CVE-2026-32825 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 7.3 CVE-2026-32824 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 8.1 CVE-2026-32821 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-32820 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-32806 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-6793 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT … No fix yet Fix from $1,6002026-07-20 CRITICAL 9.9 CVE-2026-51027 An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. Mitigation only Fix from $2,3002026-07-20 MEDIUM 6.5 CVE-2026-51026 Directory Traversal vulnerability in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via a crafted request. No fix yet Fix from $1,6002026-07-20 CRITICAL 10.0 CVE-2026-46412 @beproduct/nestjs-auth is a NestJS authentication module for BeProduct IDS (Identity Server) with OpenID Connect support. Between 2026-05-11 20:19 UT… No fix yet Fix from $2,3002026-07-20 MEDIUM 6.1 CVE-2026-32822 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-32807 dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dataCycle-CORE, the module handl… No fix yet Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-27823 A vulnerability has been identified in EGroupware that may lead to Remote Code Execution (RCE). The issue allows an authenticated attacker to execute… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-25039 Parsec is a cloud-based application for simple and cryptographically secure file sharing. The application does not sanitize the workspace name, creat… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-21824 HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of u… No fix yet Fix from $1,9502026-07-20 HIGH 8.7 CVE-2026-45270 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the `Pages` backend module registers the `html_purify` … No fix yet Fix from $1,9502026-07-20 MEDIUM 6.5 CVE-2026-45139 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the Fileeditor module enforces an extension allowlist (… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.5 CVE-2026-16277 A stack-based buffer overflow was found in rpcbind's rpcinfo utility. When querying a remote rpcbind service with `rpcinfo -l`, address information r… No fix yet Fix from $1,6002026-07-20 HIGH 7.3 CVE-2026-16252 A security flaw has been discovered in Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System 8.2.2. Impacted is an unknown… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.0 CVE-2026-12701 A path traversal vulnerability was found in pulpcore. The relative_path_validator function only verifies that content paths do not begin with "/" but… No fix yet Fix from $2,3002026-07-20 MEDIUM 5.3 CVE-2026-57311 Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Cod… No fix yet Fix from $1,6002026-07-20 MEDIUM 6.3 CVE-2026-57310 Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to … No fix yet Fix from $1,6002026-07-20 CRITICAL 9.3 CVE-2026-57309 A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in… No fix yet Fix from $2,3002026-07-20 HIGH 8.8 CVE-2026-16248 A vulnerability was found in Tenda AC10 16.03.10.09_multi_TDE01. This issue affects the function fromAdvSetLanip of the file /goform/AdvSetLanip of t… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.3 CVE-2026-16244 A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality… No fix yet Fix from $1,6002026-07-20 HIGH 7.3 CVE-2026-12080 A flaw was found in the QEMU Guest Agent (qga). A local unprivileged user can exploit a vulnerability in the guest-ssh-add-authorized-keys command ha… No fix yet Fix from $1,9502026-07-20 HIGH 8.6 CVE-2026-64623 Network-AI before 5.13.4 contains an improper cryptographic signature verification vulnerability in APSAdapter where the default local verifier accep… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-64622 Network-AI (npm: network-ai) versions 5.12.2 through 5.13.3 fail to apply the configured authorization check (checkAuth/secret) to the ApprovalInbox … No fix yet Fix from $1,9502026-07-20 HIGH 7.3 CVE-2026-16247 In _connect.BRAIN versions prior to 5.06, the application LogPathConfig.exe is executed during setup. During this process, existing permissions on %P… No fix yet Fix from $1,9502026-07-20 HIGH 7.3 CVE-2026-16246 In BRAIN2 versions prior to 3.09, the application LogPathConfig.exe is executed during setup. As a result, the Windows group Everyone is granted full… No fix yet Fix from $1,9502026-07-20