Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2026-13040 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter … Mitigation only Fix from $1,9502026-07-03 MEDIUM 5.5 CVE-2026-11397 The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_i… No fix yet Fix from $1,6002026-07-03 MEDIUM 6.0 CVE-2026-12960 An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a c… Mitigation only Fix from $1,6002026-07-03 HIGH 8.5 CVE-2026-8921 External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via… Mitigation only Fix from $1,9502026-07-03 HIGH 7.3 CVE-2022-4990 ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass securi… Mitigation only Fix from $1,9502026-07-03 HIGH 8.5 CVE-2022-4989 ** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access uninte… Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.4 CVE-2026-12734 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-12731 The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '… Mitigation only Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-14327 The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter pa… Mitigation only Fix from $1,9502026-07-03 MEDIUM 5.3 CVE-2026-55726 The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access an… Mitigation only Fix from $1,6002026-07-03 MEDIUM 5.4 CVE-2026-54477 The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks. Mitigation only Fix from $1,6002026-07-03 CRITICAL 10.0 CVE-2026-13768 Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic… Mitigation only Fix from $2,3002026-07-03 MEDIUM 6.9 CVE-2026-13371 An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to th… Mitigation only Fix from $1,6002026-07-03 HIGH 8.8 CVE-2026-57100 Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne… Entra Provisioning Service Mitigation only Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-54998 Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. Exchange Online No fix yet Fix from $1,9502026-07-02 HIGH 8.8 CVE-2026-45499 Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network. Azure Openai Mitigation only Fix from $1,9502026-07-02 CRITICAL 9.3 CVE-2026-41106 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-26145 Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Azure Synapse No fix yet Fix from $2,3002026-07-02 MEDIUM 6.5 CVE-2026-52188 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead//sub_49… Mitigation only Fix from $1,6002026-07-02 CRITICAL 9.4 CVE-2026-52830 fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se… No fix yet Fix from $2,3002026-07-02 HIGH 7.5 CVE-2026-52192 An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component Mitigation only Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-52191 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_444… Mitigation only Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-52189 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_487… Mitigation only Fix from $1,9502026-07-02 MEDIUM 5.4 CVE-2026-59102 Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in oth… Mitigation only Fix from $1,6002026-07-02 MEDIUM 5.9 CVE-2026-58580 LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, upda… Mitigation only Fix from $1,6002026-07-02 MEDIUM 6.1 CVE-2026-58381 A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially craf… Mitigation only Fix from $1,6002026-07-02 HIGH 7.5 CVE-2026-58467 Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f… Mitigation only Fix from $1,9502026-07-02 HIGH 7.5 CVE-2026-52187 Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_483… Mitigation only Fix from $1,9502026-07-02 HIGH 8.1 CVE-2026-7311 The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati… Mitigation only Fix from $1,9502026-07-02 HIGH 7.0 CVE-2026-8699 A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insuffi… Mitigation only Fix from $1,9502026-07-02