Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-29519 Lucee CFML Server versions across the 5.3.x, 6.1.x, 6.2.x, and 7.0.x release lines contain a reflected cross-site scripting vulnerability in URL path… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.0 CVE-2026-41880 R-SOFT DMS is vulnerable to OS Command Injection in the Optical Character Recognition (OCR) module. Multiple command execution functions accept user-… Mitigation only Fix from $2,3002026-07-10 HIGH 8.2 CVE-2026-41879 R-SOFT DMS stores superadmin credentials using a non-salted nested MD5 hash. This allows an attacker who obtain password hash to decode superadmin cr… Mitigation only Fix from $1,9502026-07-10 HIGH 7.1 CVE-2026-41878 R-SOFT DMS is vulnerable to Insecure Direct Object Reference (IDOR) attack in multiple file download endpoints. The application fetches files from th… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.1 CVE-2026-41877 R-SOFT DMS is vulnerable to Stored XSS in file upload functionality. Authenticated attacker can inject arbitrary HTML and JS into the name of the fil… Mitigation only Fix from $1,6002026-07-10 HIGH 8.7 CVE-2026-41876 R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.3 CVE-2026-15378 A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request Forgery … Mitigation only Fix from $2,3002026-07-10 MEDIUM 6.4 CVE-2026-13710 The Jeg Kit for Elementor – Powerful Addons for Elementor, Widgets & Templates for WordPress plugin for WordPress is vulnerable to Stored Cross-Site … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-13247 The Logo Slider – Logo Carousel, Client Logo Slider & Brand Showcase for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-13010 The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL Injection via 'event' Shortco… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.3 CVE-2026-11990 The KiviCare – Clinic & Patient Management System (EHR) plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.1 CVE-2026-9838 The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and inc… Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.3 CVE-2026-6802 The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-3907 The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wphostel-book' shortcode in all versions up to and including 1.… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.5 CVE-2026-15104 The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to generic SQL Injection via the … Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-12924 The Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered) plugin for WordPress is vulnerable to Stored Cross-Site Scripting vi… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.6 CVE-2025-11977 The Happyforms – Form Builder for WordPress: Drag & Drop Contact Forms, Surveys, Payments & Multipurpose Forms plugin for WordPress is vulnerable to … Mitigation only Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-40454 Out-of-bounds Read, Improper Input Validation vulnerability in Apache IoTDB C++ client. Out-of-bounds reads in IoTDB C++ client TsBlock deserializer … Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-40452 Incorrect Authorization, Improper Access Control vulnerability in Apache IoTDB. Authorization bypass in /rest/v2/fastLastQuery exposes last-value dat… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.5 CVE-2026-40009 Improper Privilege Management, Improper Access Control vulnerability in Apache IoTDB. Authenticated users can escalate to full tree-path access by re… Mitigation only Fix from $1,6002026-07-10 CRITICAL 9.8 CVE-2026-40008 Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache IoTDB. The pipe processor reads a fully qu… Mitigation only Fix from $2,3002026-07-10 HIGH 7.5 CVE-2026-40007 Uncontrolled Recursion, Uncontrolled Resource Consumption vulnerability in Apache IoTDB. When pipe_air_gap_receiver_enabled=true, the IoTDB AirGap re… Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-40006 Memory Allocation with Excessive Size Value, Allocation of Resources Without Limits or Throttling, Missing Authentication for Critical Function vulne… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.1 CVE-2026-40005 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. An attacker can write arbitrary files a… Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.8 CVE-2026-28564 Insufficient Session Expiration, Authentication Bypass by Capture-replay vulnerability in Apache IoTDB. REST Basic Authentication Accepts Stale Cache… Mitigation only Fix from $2,3002026-07-10 HIGH 7.5 CVE-2026-13347 The Hide My WP Lite plugin for WordPress is vulnerable to Arbitrary File Read in versions up to and including 1.3 via the he_wrapper_js and he_wrappe… Mitigation only Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-12685 The EscortWP escortwp WordPress theme through 3.6.2 was distributed with a vendor-authored, obfuscated backdoor that lets an unauthenticated attacker… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.3 CVE-2026-12276 The LA-Studio Element Kit for Elementor WordPress plugin before 1.6.1 does not check whether user registration is enabled on the site before creating… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-12123 The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'v… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.8 CVE-2026-21057 Improper input validation in Samsung Pass prior to version 5.2.10.3 allows local privileged attackers to write out-of-bounds memory. Mitigation only Fix from $1,6002026-07-10