Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-45870 LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to Local File Inclusion (LFI) in the OnlyOfficeEditor servlet class, allowing authenticated … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.0 CVE-2026-10587 A potential out-of-bounds write vulnerability could allow a local privileged attacker to modify power management settings in System Management Mode. No fix yet Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-63082 Perfect Support Ticketing & Document Management System through 1.7 contains a broken access control vulnerability that allows authenticated attackers… No fix yet Fix from $1,6002026-07-16 MEDIUM 5.4 CVE-2026-63081 Perfect Support Ticketing & Document Management System through 1.7 contains a stored cross-site scripting vulnerability that allows authenticated att… No fix yet Fix from $1,6002026-07-16 HIGH 8.6 CVE-2026-57206 SimpleChat is a secure AI conversation application with personal and group workspaces for document-grounded interactions. Prior to 0.241.206, several… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.8 CVE-2026-12379 An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not prop… No fix yet Fix from $1,6002026-07-16 HIGH 8.8 CVE-2025-45868 LogicalDOC Enterprise up to and for v9.1.1 is vulnerable to blind SQL injection in the ComparisonServlet component, allowing authenticated user to ma… No fix yet Fix from $1,9502026-07-16 HIGH 7.5 CVE-2026-59862 Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.32.0, Kiota's Python generator let attacker-controlled enum value descrip… No fix yet Fix from $1,9502026-07-16 HIGH 8.3 CVE-2026-14254 A race condition in the account lockout mechanism in Delphix Continous Data allowed the lockout threshold to be bypassed through concurrent authentic… No fix yet Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-5674 A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as Flatpak, by exploi… Mitigation only Fix from $1,9502026-07-16 MEDIUM 5.5 CVE-2026-9494 An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT … No fix yet Fix from $1,6002026-07-16 HIGH 8.6 CVE-2026-63306 stoatchat before 0.13.5 contains an unauthenticated server-side request forgery vulnerability in the /proxy and /embed endpoints that accept arbitrar… No fix yet Fix from $1,9502026-07-16 HIGH 8.1 CVE-2026-63305 AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are conca… No fix yet Fix from $1,9502026-07-16 HIGH 8.1 CVE-2026-63304 AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function in… Mitigation only Fix from $1,9502026-07-16 MEDIUM 5.0 CVE-2026-12391 An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs comma… No fix yet Fix from $1,6002026-07-16 CRITICAL 9.0 CVE-2026-11386 An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT so… No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2023-49900 An unauthenticated remote attacker is able to perform remote code execution due to incorrectly sanitized user input in the SetParameter command. No fix yet Fix from $2,3002026-07-16 CRITICAL 9.8 CVE-2023-49899 An unauthenticated remote attacker can execute any command on the affected device due to not correctly verifying the origin of a communication channe… Mitigation only Fix from $2,3002026-07-16 CRITICAL 9.6 CVE-2026-22752 Authentication bypass by primary weakness vulnerability in Spring Security Spring Authorization Server. This issue affects Spring Authorization Serv… No fix yet Fix from $2,3002026-07-16 HIGH 7.2 CVE-2026-7543 The Breakdance plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'fields' parameter in versions up to, and including, 2.7.1 d… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.7 CVE-2026-6424 Use-after-free vulnerability in ESET Linux products potentially allowed an attacker to trigger kernel panic on the system No fix yet Fix from $1,6002026-07-16 HIGH 8.5 CVE-2026-6423 A local privilege escalation vulnerability in ESET Inspect Connector.  The vulnerability was caused by improper authentication in an IPC channel. Mitigation only Fix from $1,9502026-07-16 HIGH 8.7 CVE-2026-58078 Joomla Extension - themexpert.com - Unauthenticated SQL injection in Quix Page Builder Pro < 6.2.1 - The Joomla extension Quix Page Builder Pro is vu… No fix yet Fix from $1,9502026-07-16 MEDIUM 5.3 CVE-2026-15106 The WPBot – AI ChatBot for Live Support, Lead Generation, AI Services plugin for WordPress is vulnerable to authorization bypass in all versions up t… No fix yet Fix from $1,6002026-07-16 HIGH 8.8 CVE-2026-15103 The WPFunnels – Funnel Builder for WooCommerce with Checkout & One Click Upsell plugin for WordPress is vulnerable to Privilege Escalation via arbitr… No fix yet Fix from $1,9502026-07-16 MEDIUM 6.4 CVE-2026-15099 The Delicious Recipes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'steps' block attribute in versions up to, and includ… No fix yet Fix from $1,6002026-07-16 MEDIUM 6.5 CVE-2026-15022 The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via Stored Quiz Answer Array in all … No fix yet Fix from $1,6002026-07-16 MEDIUM 6.4 CVE-2026-15021 The wpForo Forum plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'location' Profile Field in all versions up to, and including,… No fix yet Fix from $1,6002026-07-16 HIGH 8.1 CVE-2026-15008 The Uncanny Automator – Easy Automation, Integration, Webhooks & Workflow Builder Plugin plugin for WordPress is vulnerable to arbitrary file deletio… No fix yet Fix from $1,9502026-07-16 HIGH 8.8 CVE-2026-15005 The Loco Translate plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.8.5. This is due to missi… Mitigation only Fix from $1,9502026-07-16