Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-34111 Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"php… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34110 Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php … Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34109 Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/sp… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34108 Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34107 Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34106 Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34105 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, ext… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34104 Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34103 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extensio… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34102 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where i… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34101 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extensio… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34100 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, t… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-34099 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = … Mitigation only Fix from $2,3002026-07-01 MEDIUM 5.3 CVE-2026-27409 Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This iss… Mitigation only Fix from $1,6002026-07-01 HIGH 7.5 CVE-2026-20191 A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.&nbsp; … Mitigation only Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-58036 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with p… Mediawiki Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-57517 Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQ… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.8 CVE-2026-24270 NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lea… Mitigation only Fix from $2,3002026-07-01 HIGH 8.5 CVE-2026-24260 NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use race condition. A successful ex… Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.0 CVE-2025-23351 NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.0 CVE-2025-23350 NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write… Mitigation only Fix from $2,3002026-07-01 HIGH 7.6 CVE-2026-6688 FatFs R0.16 and earlier contains a downstream-caller vulnerability pattern associated with FatFs long filename handling. With LFN enabled, fno.fname … Fatfs No fix yet Fix from $1,9502026-07-01 HIGH 7.6 CVE-2026-6687 FatFs R0.16 and earlier contains a stack overflow bug in f_getlabel() because exFAT label length (XDIR_NumLabel) is trusted without enforcing spec ma… Fatfs No fix yet Fix from $1,9502026-07-01 MEDIUM 6.1 CVE-2026-6685 FatFs R0.16 and earlier exhibits a stale dirty-cache skip via unsigned-subtraction wrap in f_read() / f_write() (fp->sect - sect < cc) during interle… Fatfs No fix yet Fix from $1,6002026-07-01 HIGH 7.6 CVE-2026-6682 In FatFS R0.16 and earlier contains a FAT32 integer overflow bug in mount_volume() where fasize *= fs->n_fats can wrap, leading to attacker-controlle… Fatfs No fix yet Fix from $1,9502026-07-01 MEDIUM 5.4 CVE-2026-6283 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-5220 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyD… Mitigation only Fix from $1,6002026-07-01 HIGH 8.7 CVE-2026-58399 @acastellon/auth is an authentication control system for microservices. Versions prior to 2.3.0 appear to allow an unauthenticated authentication byp… Mitigation only Fix from $1,9502026-07-01 MEDIUM 5.4 CVE-2026-58031 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This v… Mediawiki Mitigation only Fix from $1,6002026-07-01 HIGH 8.2 CVE-2026-2891 The following Poly Voice IP devices, CCX, Trio, and Edge E, might be inoperable if they connect to a malicious SIP server and receive malformed data.… Mitigation only Fix from $1,9502026-07-01