Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.3 CVE-2026-15684 Glarysoft Glary Utilities Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges o… Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-15683 Lorex 2K Indoor Wi-Fi Security Camera Device Management Server Improper Certificate Validation Vulnerability. This vulnerability allows network-adjac… Mitigation only Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-15680 Lorex 2K Indoor Wi-Fi Security Camera CDeviceOperator Format String Remote Code Execution Vulnerability. This vulnerability allows network-adjacent a… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-15598 A weakness has been identified in antv layout 2.0.0. This impacts the function setNestedValue in the library lib/util/object.js. Executing a manipula… Mitigation only Fix from $1,6002026-07-13 HIGH 7.3 CVE-2026-15597 A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/2.php. This affects an unknown function of the file /edit… Mitigation only Fix from $1,9502026-07-13 HIGH 7.1 CVE-2026-58410 ChurchCRM is an open-source church management system. Prior to version 7.4.0, there was an authorization flaw in the family-scoped endpoints which al… Mitigation only Fix from $1,9502026-07-13 CRITICAL 9.1 CVE-2026-58409 ChurchCRM is an open-source church management system. Prior to version 7.4.0, an authenticated administrator can achieve Remote Code Execution (RCE) … Mitigation only Fix from $2,3002026-07-13 HIGH 8.2 CVE-2026-48364 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code… Coldfusion Mitigation only Fix from $1,9502026-07-13 HIGH 8.2 CVE-2026-48363 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code… Coldfusion Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.5 CVE-2026-58408 ChurchCRM is an open-source church management system. Prior to version 7.4.0, a low-privileged user can bypass the /admin/export UI and exfiltrate th… Mitigation only Fix from $1,6002026-07-13 HIGH 8.8 CVE-2026-55773 CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3… Mitigation only Fix from $1,9502026-07-13 HIGH 8.8 CVE-2026-55771 CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 4.9… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.4 CVE-2026-12536 The Avada (Fusion) Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘Module Title’ parameter in all versions up to, … Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.5 CVE-2026-6875EPSS 27% ServiceNow has addressed a remote code execution vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an … Mitigation only Fix from $2,3002026-07-13 HIGH 8.8 CVE-2026-55772 CedarJava is an open source Java implementation of the Cedar policy language, used for fine-grained authorization decisions. In versions prior to 2.3… No fix yet Fix from $1,9502026-07-13 HIGH 7.5 CVE-2026-26396 OpenBMB XAgent v1.0.0 and before is vulnerable to path traversal in the file() function in XAgent/XAgentServer/application/routers/workspace.py. The … Mitigation only Fix from $1,9502026-07-13 HIGH 7.3 CVE-2025-45869 LogicalDOC Enterprise Version up to and before v9.1.1 is vulnerable to Server-Side Request Forgery (SSRF). An unauthenticated attacker can exploit th… Mitigation only Fix from $1,9502026-07-13 MEDIUM 5.3 CVE-2026-61505 Rejetto HFS 3.0.0 through 3.2.0 allows path traversal through the lang query parameter, permitting a remote unauthenticated attacker to read certain … Mitigation only Fix from $1,6002026-07-13 MEDIUM 5.4 CVE-2026-61504 Rejetto HFS 3.0.0 through 3.2.0 does not escape file names in its fallback "basic" web listing, and this listing can be forced by any browser via the… Mitigation only Fix from $1,6002026-07-13 MEDIUM 5.3 CVE-2026-61503 Rejetto HFS 3.0.0 through 3.2.0 returns observably different responses from its login endpoint depending on whether the submitted username exists. A … Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.1 CVE-2026-61501 Rejetto HFS 3.0.0 through 3.2.0 renders log entries in the administration panel as HTML without sanitization. A remote unauthenticated attacker can s… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.8 CVE-2026-61500 Rejetto HFS 3.0.0 through 3.2.0 derives its session-cookie signing key from the non-cryptographic Math.random() generator and discloses outputs of th… Mitigation only Fix from $2,3002026-07-13 MEDIUM 6.1 CVE-2026-60103 Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by sup… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.3 CVE-2026-6847 Remote Code Execution vulnerability exists in ThemisNETPanel due to missing authentication for a critical file upload function. The application expos… Mitigation only Fix from $2,3002026-07-13 HIGH 7.5 CVE-2026-15584 A privilege escalation vulnerability was found in the incluster-checks tool for OpenShift. The tool creates privileged debug pods with host filesyste… Mitigation only Fix from $1,9502026-07-13 MEDIUM 6.3 CVE-2026-15559 A vulnerability was detected in CodeAstro Simple Online Leave Management System 1.0. This affects an unknown part of the file /SimpleOnlineLeave/admi… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.5 CVE-2026-62147 The Tempo Operator's gateway component failed to consistently apply namespace-scoped redaction on some query API response paths when query RBAC was e… Mitigation only Fix from $1,6002026-07-13 MEDIUM 6.3 CVE-2026-15558 A security vulnerability has been detected in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionali… Mitigation only Fix from $1,6002026-07-13 CRITICAL 9.3 CVE-2026-12257 Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/… Mitigation only Fix from $2,3002026-07-13 MEDIUM 5.1 CVE-2026-4765 Stored Cross-Site Scripting (XSS) vulnerability in the RD Station Conversas chat. The vulnerability resides in the ‘name’ parameter of the initializa… Mitigation only Fix from $1,6002026-07-13