Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-13461 When coupled with the SSL bypass vulnerability, JavaScript can be injected into a WebView in the PayRange version 7.0.7 app. The injection of specifi… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-42486 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d… No fix yet Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23562 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23561 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d… Mitigation only Fix from $2,3002026-07-09 MEDIUM 6.3 CVE-2026-15189 A security vulnerability has been detected in aerostackdev aerostack-mcp up to 6315dfde7df0a15aaf743f88d91347115e09ba23. Affected by this issue is th… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.3 CVE-2026-15188 A weakness has been identified in manjurulhoque django-job-portal up to dfa352f305bba44445ac5dc12e9b2a98c9dcd71f. Affected by this vulnerability is t… Mitigation only Fix from $1,6002026-07-09 CRITICAL 9.4 CVE-2026-23560 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure d… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23559 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] XAPI can configure… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2026-23556 When oxenstored is tearing a domain down, the node data is cleaned up but the usage counts are leaked. When the domain ID is eventually reused, the … Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-58151 varstored is a component of the Xapi toolstack handling UEFI Variables for a VM. It has a communication path with OVMF inside the VM involving mappi… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-58146 There are multiple issues. 1. Updates to the XAPI database sanitise input strings, but try generating the notification using the unsanitised in… No fix yet Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27464 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27463 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drive… Mitigation only Fix from $2,3002026-07-09 CRITICAL 9.4 CVE-2025-27462 [This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV dri… Mitigation only Fix from $2,3002026-07-09 MEDIUM 5.4 CVE-2026-5005 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Twiser Informatics Technology Consulting, Trade… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.7 CVE-2026-54799 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0).… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-54798 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0).… Mitigation only Fix from $1,6002026-07-09 HIGH 7.2 CVE-2026-54801 A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.20), SICORE Base system (All versions < V26.20.0).… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.5 CVE-2026-60095 Vinchin Backup & Recovery through 9.0.0.86562 contains a stack buffer overflow vulnerability in the ModuleHandShake function of the agentlink_server … Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-60094 Vinchin Backup & Recovery through 9.0.0.86562 contains a heap buffer overflow vulnerability that allows unauthenticated remote attackers to cause pro… Mitigation only Fix from $1,6002026-07-09 HIGH 8.2 CVE-2026-4256 Improper neutralization of special elements used in an LDAP query ('LDAP injection') vulnerability in PEAKUP Technology Inc. PassGate allows LDAP Inj… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-15186 A vulnerability was identified in macrozheng mall up to 1.0.3. This impacts an unknown function of the file /returnApply/create of the component Port… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.9 CVE-2026-12879 An Improper Input Validation vulnerability in BigQuery DAO in Google Cloud Apigee versions prior to 2026-06-12 on Google Cloud Platform allows an aut… Mitigation only Fix from $1,6002026-07-09 HIGH 8.7 CVE-2026-12593 The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for crea… Mitigation only Fix from $1,9502026-07-09 HIGH 7.2 CVE-2026-9253 The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' … Mitigation only Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-9028 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. Thi… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-9027 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature i… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-9021 The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin regi… Mitigation only Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-59692 A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name … Mitigation only Fix from $1,9502026-07-09 HIGH 7.1 CVE-2026-59691 A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 1… Mitigation only Fix from $1,9502026-07-09