Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-49147 App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a file… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-49145 App::Ack versions through 3.10.0 for Perl read arbitrary files via --files-from in a project .ackrc. ack searches up the directory hierarchy from th… Mitigation only Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-24700 An OS command injection vulnerability exists in the start_lltd() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W … Rv130 Firmware No fix yet Fix from $1,9502026-07-08 MEDIUM 6.3 CVE-2026-15044 A flaw was found in the TrustyAI Service Operator. When deploying services like gorch or NemoGuardrails, if a specific security setting is not enable… Mitigation only Fix from $1,6002026-07-08 HIGH 7.2 CVE-2026-24699 An OS command injection vulnerability exists in the sub_34984() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV110W r… Rv130 Firmware Mitigation only Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-24698 An OS command injection vulnerability exists in the save_syslog_to_file() function of the "httpd" binary in Cisco RV130/RV130W with firmware 1.0.3.55… Rv130 Firmware Mitigation only Fix from $1,9502026-07-08 HIGH 7.2 CVE-2026-24697 An OS command injection vulnerability exists in the start_bonjour() function of the "rc" binary in Cisco RV130/RV130W with firmware 1.0.3.55 and RV11… Rv130 Firmware Mitigation only Fix from $1,9502026-07-08 HIGH 8.8 CVE-2026-15067 Snowflake Terraform Provider versions prior to 2.18.0 contain several security vulnerabilities, including SQL injection via an unsanitized data sourc… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.6 CVE-2026-15062 SQL injection vulnerabilities in the Snowflake Snowpark Python SDK (snowpark-python) versions prior to 1.53.0 could allow authenticated low-privilege… Mitigation only Fix from $2,3002026-07-08 HIGH 7.5 CVE-2026-10708 This vulnerability enables large‑scale data harvesting without requiring app‑specific secrets. A single request to a minimal leaderboard component ma… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-10706 In Adalo’s no-code app builder, (Versions 1 and 2) the attackers may extract full user records and correlate user behavior across multiple applicatio… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-58656 Grav API plugin before v1.0.0-rc.16 accepts JWT tokens via the ?token= URL query parameter and responds with Access-Control-Allow-Origin: *, allowing… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.8 CVE-2026-58480 Blocksy Companion Pro plugin for WordPress before 2.1.47 contains an unauthenticated arbitrary file upload vulnerability that allows attackers to upl… Mitigation only Fix from $2,3002026-07-08 MEDIUM 5.4 CVE-2026-56293 Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org when transferring applications b… Mitigation only Fix from $1,6002026-07-08 MEDIUM 5.3 CVE-2026-56284 Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC function public.get_total_metrics… Mitigation only Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-56283 Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attackers to inject malicious HTML c… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-56273 Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that accept unsanitized basePath p… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.5 CVE-2026-56220 Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows read-only org members to insert… Mitigation only Fix from $1,6002026-07-08 HIGH 7.5 CVE-2026-56250 Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, enabling retargeting to arbit… Mitigation only Fix from $1,9502026-07-08 HIGH 8.1 CVE-2026-56246 Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped API key (limited_to_orgs) inhe… Mitigation only Fix from $1,9502026-07-08 HIGH 7.5 CVE-2026-56226 Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which is SECURITY DEFINER and grant… Mitigation only Fix from $1,9502026-07-08 CRITICAL 9.1 CVE-2026-54061 Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for external snapshot import on th… Mitigation only Fix from $2,3002026-07-08 MEDIUM 6.3 CVE-2026-15033 A flaw has been found in christopherthielen check-peer-dependencies up to 4.3.4. Affected by this vulnerability is the function shelljs.exec of the f… Mitigation only Fix from $1,6002026-07-08 MEDIUM 5.4 CVE-2026-8315 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Stored X… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.1 CVE-2026-8310 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Webbeyaz Web Design Mediküm Web allows Reflecte… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2026-6740 The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'co… Mitigation only Fix from $1,6002026-07-08 MEDIUM 6.4 CVE-2026-6459 The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … Mitigation only Fix from $1,6002026-07-08 CRITICAL 9.8 CVE-2026-8307 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Webbeyaz Web Design Mediküm Web allows SQL Inje… Mitigation only Fix from $2,3002026-07-08 HIGH 7.2 CVE-2026-6820 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'email' parameter in all versions… Mitigation only Fix from $1,9502026-07-08 MEDIUM 5.3 CVE-2026-5459 The User Frontend: AI Powered Frontend Posting, User Directory, Profile, Membership & User Registration plugin for WordPress is vulnerable to Insecur… Mitigation only Fix from $1,6002026-07-08