Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-60085 PraisonAI before 4.6.78 contains an unenforced security policy vulnerability in the default Subprocess Sandbox backend where blocked_commands, blocke… Mitigation only Fix from $1,9502026-07-15 MEDIUM 6.3 CVE-2026-59254 n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in workflow node expressions outsi… Mitigation only Fix from $1,6002026-07-15 HIGH 8.8 CVE-2026-58655 The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side template injection vulnerability. … Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-57996 phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAdmin administrators to create … Mitigation only Fix from $1,9502026-07-15 CRITICAL 10.0 CVE-2026-56699 Wazuh Manager before 5.0.0-beta3 fails to escape the DataValue.index field when constructing OpenSearch bulk requests, allowing enrolled agents to in… Mitigation only Fix from $2,3002026-07-15 MEDIUM 6.4 CVE-2026-56352 n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, which reads workflow files fr… Mitigation only Fix from $1,6002026-07-15 MEDIUM 6.3 CVE-2026-56349 n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypass default guardrail instruct… Mitigation only Fix from $1,6002026-07-15 HIGH 7.5 CVE-2026-56339 Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY DEFINER RPC function public.… Mitigation only Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-58077 Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate… Mitigation only Fix from $1,9502026-07-15 HIGH 8.6 CVE-2026-57833 Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticate… Mitigation only Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-57832 Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocman is vulnerable to an unauthe… Mitigation only Fix from $1,9502026-07-15 HIGH 8.7 CVE-2026-57831 Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla extension DP Calendar is vulne… Mitigation only Fix from $1,9502026-07-15 HIGH 8.8 CVE-2026-15804 The HCM developed by MetaGuru has a SQL Injection vulnerability. Authenticated remote attackers can inject SQL commands via specific parameters, ther… Mitigation only Fix from $1,9502026-07-15 HIGH 8.6 CVE-2026-15583 A confused-deputy flaw in Grafana MCP Server allows an unauthenticated remote attacker to exfiltrate the server's environment-configured Grafana serv… Mitigation only Fix from $1,9502026-07-15 HIGH 7.7 CVE-2026-14251 A flaw was found in the OpenShift GitOps operator. The ClusterRole reconciler does not validate resource ownership when reconciling ClusterRole objec… Mitigation only Fix from $1,9502026-07-15 HIGH 7.8 CVE-2026-42936 The installer of HYPER SBI 2 insecurely loads Dynamic Link Libraries. If there is a crafted DLL at the same directory when invoking the affected inst… Mitigation only Fix from $1,9502026-07-15 HIGH 8.6 CVE-2026-12512 The Quotes llama WordPress plugin before 3.1.6 does not properly sanitize and escape a user-supplied parameter before using it in a SQL query, allowi… Mitigation only Fix from $1,9502026-07-15 HIGH 8.1 CVE-2026-12281 The Shibboleth WordPress plugin before 2.5.4 does not fail closed when its HTTP header identity mode is enabled without an anti-spoofing key, treatin… Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.5 CVE-2026-11580 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not perform a per-object capability check in its post-dupli… Mitigation only Fix from $1,6002026-07-15 MEDIUM 5.3 CVE-2026-11579 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.17 does not verify that a file upload is made against an existing f… Mitigation only Fix from $1,6002026-07-15 HIGH 8.5 CVE-2026-8920 Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local… Mitigation only Fix from $1,9502026-07-15 HIGH 7.2 CVE-2026-8919 Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing … Mitigation only Fix from $1,9502026-07-15 MEDIUM 5.6 CVE-2026-15030 Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read… Mitigation only Fix from $1,6002026-07-15 HIGH 8.4 CVE-2026-15029 Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administra… Mitigation only Fix from $1,9502026-07-15 HIGH 8.2 CVE-2026-13585 Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Inter… Mitigation only Fix from $1,9502026-07-15 CRITICAL 9.5 CVE-2026-13385 An Improper Validation of Integrity Check Value and Improper Certificate Validation in certain ASUS router models allows a remote man-in-the-middle(M… Mitigation only Fix from $2,3002026-07-15 MEDIUM 5.9 CVE-2026-11851 Improper Neutralization of Special Elements used in an SQL Command ("SQL Injection") in the web management interface of certain ASUS router models al… Mitigation only Fix from $1,6002026-07-15 CRITICAL 9.8 CVE-2026-5270 An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.8 CVE-2026-5269 In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operation… No fix yet Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-36035 Incorrect access control in the /api/License/deactivateOffline endpoint of CAXPerts UniversalPlantViewer WebServices Server v2.7.6 allows authenticat… Mitigation only Fix from $1,6002026-07-14