Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-47831 Use of a cryptographically weak random number generator in the GenerateRandomPassword function in bosh-windows-stemcell-builder allows a remote attac… Mitigation only Fix from $1,9502026-07-09 HIGH 8.8 CVE-2026-47830 Incorrect Permission Assignment in BOSH.Utils.psm1 in BOSH-Ecosystem bosh-windows-stemcell-builder allows low-privilege authenticated users to overwr… Mitigation only Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-12517 The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated site-… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-12516 The Fediverse Embeds WordPress plugin before 1.5.8 does not validate the destination of the server-side request performed by an unauthenticated media… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.5 CVE-2026-12270 The Everest Forms WordPress plugin before 3.5.0 does not correctly restrict access to several REST API endpoints belonging to its onboarding assista… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-11875 The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sign or verify its guest-session cookie, allowing unauthenticate… Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-11869 The WP DSGVO Tools (GDPR) WordPress plugin before 3.1.40 does not perform an authorization check on the immediate-processing path of its data subject… Mitigation only Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-11571 The Everest Forms WordPress plugin before 3.5.0 does not reliably delete temporary CSV files generated during email-notification processing and leav… Mitigation only Fix from $1,9502026-07-09 HIGH 8.8 CVE-2026-5523 The Divi Form Builder plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 5.1.8. This is due to the update_… Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-15138 A security vulnerability has been detected in tumf mcp-text-editor up to 1.0.2. This issue affects the function _validate_file_path of the file mcp_t… Mitigation only Fix from $1,6002026-07-09 MEDIUM 6.1 CVE-2026-47646 Improper neutralization of input during web page generation ('cross-site scripting') in Dynamics 365 Customer Voice allows an unauthorized attacker t… Dynamics 365 Customer Voice Mitigation only Fix from $1,6002026-07-09 HIGH 7.3 CVE-2026-15137 A weakness has been identified in code-projects Interview Management System 1.0. This vulnerability affects unknown code of the file \inc\classes\Vie… Mitigation only Fix from $1,9502026-07-09 HIGH 7.3 CVE-2026-15135 A security flaw has been discovered in code-projects Online Food Order System 1.0. This affects an unknown part of the file /edit_food_items.php. The… Mitigation only Fix from $1,9502026-07-09 HIGH 7.3 CVE-2026-15134 A vulnerability was determined in CodeAstro Simple Online Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of … Mitigation only Fix from $1,9502026-07-09 MEDIUM 6.3 CVE-2026-15105 A flaw has been found in davenardella snap7 up to 1.4.3. This affects the function TS7Worker::PerformFunctionRead of the file src/core/s7_server.cpp … No fix yet Fix from $1,6002026-07-08 MEDIUM 6.0 CVE-2026-5923 Malicious use of a stolen cookie might allow modifications to the contents of the IP phone’s webpage. No fix yet Fix from $1,6002026-07-08 MEDIUM 5.9 CVE-2026-5922 The IP phone might use malicious input stored in configuration parameters and render it as content for the WebUI’s webpage. Mitigation only Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-52200 An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the /ajax web management API endpoint … Mitigation only Fix from $2,3002026-07-08 HIGH 7.5 CVE-2026-51535 In OpENer 2.3.0 (commit 76b95cf), a resource exhaustion (Denial of Service) vulnerability exists in its network processing loop. Mitigation only Fix from $1,9502026-07-08 HIGH 8.1 CVE-2026-35552 In CAXperts UPVWebServices 2.4.2212.603 through 2.7.6 and UDiTH Portal 2026.0.0 through 2026.2.0, an authenticated remote user can invoke an administ… Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-10037 A sandbox escape vulnerability exists in the OpenJDK packages provided in Ubuntu. The .jar MIME handlers installed by these packages execute files ma… Mitigation only Fix from $1,9502026-07-08 HIGH 8.6 CVE-2026-60105 Monsta FTP before 2.14.5 contains a server-side request forgery vulnerability in the fetchRemoteFile action caused by an incomplete IP blocklist chec… Mitigation only Fix from $1,9502026-07-08 HIGH 8.2 CVE-2026-59802 PasswordPusher before 2.8.1 accepts data URI schemes in URL push payloads due to insufficient validation in the valid_url function. Attackers can cre… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.8 CVE-2026-36028 A protection mechanism failure in the Code 27 Companion Hub allows an attacker with physical access to completely bypass kiosk restrictions via a fac… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.8 CVE-2026-36027 An issue in Code27 Companion Hub SQ3A.220705.003.A1 allows a physically proximate attacker to execute arbitrary code via the USB debugging (ADB) and … Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-15154 A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (R… Openshift Ai Mitigation only Fix from $1,6002026-07-08 HIGH 8.7 CVE-2026-14891 HashiCorp Nomad and Nomad Enterprise are vulnerable to a sandbox escape in the Docker task driver that may allow a job submitter to bind-mount a host… Mitigation only Fix from $1,9502026-07-08 HIGH 7.7 CVE-2026-14373 HashiCorp Nomad and Nomad Enterprise did not enforce the allow_privileged restriction for the Docker task driver's host namespace mode options. This … Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-53951 Copier is a library and CLI app for rendering project templates. In versions 9.5.0 through 9.15.1, the `trust` setting's prefix match (`copier/_setti… Mitigation only Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-15063 A flaw was found in the gorch service template, which is part of the trustyai-service-operator. Even when authentication is enabled, the gorch servic… Mitigation only Fix from $1,6002026-07-08