Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.7 CVE-2025-40945 A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All version… Mitigation only Fix from $1,6002026-07-14 CRITICAL 9.0 CVE-2026-57898 In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 to 2.0.0-milestone-12, deployments using the MongoDB backend are vulnerable to an unauth… Mitigation only Fix from $2,3002026-07-14 CRITICAL 9.2 CVE-2026-15183 Multiple input validation vulnerabilities in the Snowflake Spark Connector (spark-snowflake) versions prior to 3.2.1 can allow attackers to exfiltrat… Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.5 CVE-2026-13699 In Eclipse KUKSA Databroker version 0.6.1, the kuksa.val.v2.VAL/PublishValue gRPC handler fails to validate the existence of the optional data_point … Kuksa No fix yet Fix from $1,6002026-07-14 HIGH 7.1 CVE-2026-59674 A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tumbleweed suricata package allows the suricata user to escalate to root. Th… Mitigation only Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-15677 A weakness has been identified in code-projects Online Job Portal 1.0. This affects an unknown function of the file /JobSeekerInsert.php. Executing a… Mitigation only Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-15676 A security flaw has been discovered in code-projects Online Job Portal up to 1.0. The impacted element is an unknown function of the file /Admin/Dele… Mitigation only Fix from $1,9502026-07-14 HIGH 7.3 CVE-2026-15675 A vulnerability was identified in code-projects Online Job Portal 1.0. The affected element is an unknown function of the file /Admin/EditUser.php. S… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.3 CVE-2026-15672 A vulnerability was determined in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /intrams/admin/add_judges.p… Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-15669 A vulnerability was found in louisho5 picobot up to 0.2.0. This issue affects the function ExecTool.Execute of the file internal/agent/tools/exec.go … Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.4 CVE-2026-12988 The WP 2FA WordPress plugin before 3.1.1.2 does not verify that the email address supplied during two-factor authentication setup belongs to the use… Mitigation only Fix from $1,6002026-07-14 HIGH 8.1 CVE-2026-12583 The Newsletters WordPress plugin before 4.15 does not prevent deserialization of untrusted input that is stored through a public form, allowing unaut… Mitigation only Fix from $1,9502026-07-14 HIGH 8.1 CVE-2026-12511 The AI Engine WordPress plugin before 3.5.5 does not sanitize a user-supplied filename before using it to write a downloaded file, allowing authenti… Mitigation only Fix from $1,9502026-07-14 MEDIUM 6.5 CVE-2026-12482 A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` valid… Keras No fix yet Fix from $1,6002026-07-14 MEDIUM 5.9 CVE-2026-11567 The SureForms WordPress plugin before 2.11.1 does not properly validate the payment amount on forms that use a dynamically-sourced (variable/hidden)… Mitigation only Fix from $1,6002026-07-14 CRITICAL 9.6 CVE-2026-11563 The Word Count and Social Shares WordPress plugin through 1.0 does not validate a user-supplied file path before deletion, nor does it have proper au… Mitigation only Fix from $2,3002026-07-14 MEDIUM 5.4 CVE-2025-15665 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.1 does not escape the value of the BEAF Slider widget's shortcode field… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15668 A vulnerability has been found in louisho5 picobot up to 0.2.0. This vulnerability affects the function WebTool.Execute of the file internal/agent/to… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15629 A weakness has been identified in louisho5 picobot up to 0.2.0. Impacted is the function CreateSkill/GetSkill of the file internal/agent/tools/filesy… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15626 A vulnerability was determined in nextlevelbuilder GoClaw 3.13.3-beta.3. This affects the function writeFile of the file internal/providers/acp/tool_… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.4 CVE-2026-7640 The WP Customer Area plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'type' attribute of the `customer-area-protected-conte… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15625 A vulnerability was found in nextlevelbuilder GoClaw 3.11.3. Affected by this issue is the function ExecApprovalManager.CheckCommand of the file inte… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.3 CVE-2026-15624 A vulnerability has been found in nextlevelbuilder GoClaw 3.13.3-beta.3. Affected by this vulnerability is the function bytePlusDownloadVideo of the … Mitigation only Fix from $1,6002026-07-14 MEDIUM 5.3 CVE-2026-11802 The FoodBook Lite - Online Food Ordering System plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.5… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.4 CVE-2026-11390 The News Kit Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Site Logo Title and Single Author Box Widgets… Mitigation only Fix from $1,6002026-07-14 HIGH 7.6 CVE-2026-58233 SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when proce… Mitigation only Fix from $1,9502026-07-14 MEDIUM 5.5 CVE-2026-44769 SAP S/4HANA application Project Management (PPM-PRO) allows an attacker with high privileges to execute crafted database queries, exposing the backen… Mitigation only Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-44767 setThemeRoot() failed to enforce the sap-allowed-theme-origins allowlist. An attacker-controlled absolute cross-origin URL could be stored and used d… Mitigation only Fix from $1,6002026-07-14 CRITICAL 9.1 CVE-2026-44761 SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in … Mitigation only Fix from $2,3002026-07-14 MEDIUM 6.1 CVE-2026-44759 SAP NetWeaver Enterprise Portal allows an unauthenticated attacker to inject malicious scripts into a URL parameter. The scripts are reflected in the… Mitigation only Fix from $1,6002026-07-14