Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.5 CVE-2026-14330 Multiple unbounded alloca() calls in the PulseAudio protocol server. Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-14324 RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return. Mitigation only Fix from $1,6002026-07-01 HIGH 7.7 CVE-2026-13602 We found a chain of combining multiple weaknesses in the product that could allow an attacker to become any user in the backend and access any data: … Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-12374 Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before… Mitigation only Fix from $1,6002026-07-01 CRITICAL 9.8 CVE-2026-57692 Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a throug… Mitigation only Fix from $2,3002026-07-01 CRITICAL 9.0 CVE-2026-13603 The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technolo… Mitigation only Fix from $2,3002026-07-01 HIGH 8.1 CVE-2026-5120 A Race Condition vulnerability affecting BIOVIA Workbook from Release 2021 through Release 2026 could allow a user to access unauthorized data from a… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.5 CVE-2026-53909 MCO does not correctly validate types of uploaded files. File upload validation functionality relies only on client-side checks, which can be bypasse… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.4 CVE-2026-53907 MCO is vulnerable to Stored Cross‑Site Scripting (XSS) via the application logo upload functionality. An attacker with the ability to change the appl… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-53902 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/profile-sections/group-membership endpoint. An authenticated u… Mycomplianceoffice Mitigation only Fix from $1,6002026-07-01 HIGH 8.2 CVE-2026-53906 MCO is vulnerable to Path Disclosure and Path Traversal in file handling functionality related to data export and upload. Improper validation of the … Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-53905 MCO does not properly enforce authorization checks in the /customer/servlet/mco/webapi/admin-view-hierarchy/get-acl-tree-structure endpoint. An authe… Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 HIGH 7.1 CVE-2026-53904 MCO is vulnerable to Account Denial of Service due to improper implementation of password reset functionality. Each password reset request invalidate… Mco Mitigation only Fix from $1,9502026-07-01 HIGH 8.1 CVE-2026-53903 MCO is vulnerable to an Insecure Direct Object Reference (IDOR) vulnerability in the /customer/servlet/mco/webapi/trading-document/fetchPdfStatement … Mycomplianceoffice Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-13228 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Privilege Escalation to Administrator in ve… Mitigation only Fix from $1,9502026-07-01 HIGH 7.2 CVE-2026-12142 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '_name[]' Array Parameter i… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-10095 The WP Photo Album Plus plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtext' parameter in all versions up to, and incl… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.3 CVE-2026-27435 Missing Authorization vulnerability in WofficeIO Woffice allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.5 CVE-2026-13454 The MotoPress Appointment Booking plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and includ… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.1 CVE-2026-12754 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'layoutstyle' parameter in all… Mitigation only Fix from $1,6002026-07-01 MEDIUM 5.9 CVE-2026-56016 CGI::Session::ID::md5 versions before 4.49 for Perl generate predictable session ids from low-entropy sources. The generate_id method builds the ses… Mitigation only Fix from $1,6002026-07-01 HIGH 7.2 CVE-2026-50043 Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in SkyBridge MB-A100/MB-A110. If this vulnera… Mitigation only Fix from $1,9502026-07-01 MEDIUM 6.4 CVE-2026-13733 The Download Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'no_data_msg' Shortcode Attribute in all versions up to, a… Mitigation only Fix from $1,6002026-07-01 MEDIUM 6.4 CVE-2026-12732 The LearnPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'class_wrapper_form' shortcode attribute in versions up to, … Mitigation only Fix from $1,6002026-07-01 HIGH 8.7 CVE-2026-12577 DVP80ES3 with Improperly Implemented Security Check for Standard vulnerability. No fix yet Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-12576 DVP80ES3 with Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability. No fix yet Fix from $1,9502026-07-01 HIGH 7.5 CVE-2026-12575 DVP80ES3 with  Improper Resource Shutdown or Release vulnerability. No fix yet Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-12224 The Dokan Pro plugin for WordPress is vulnerable to privilege escalation via update_capabilities REST Endpoint in all versions up to, and including, … Mitigation only Fix from $1,9502026-07-01 HIGH 8.8 CVE-2026-12158 The RegistrationMagic – User Registration Forms Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… Mitigation only Fix from $1,9502026-07-01 CRITICAL 9.8 CVE-2026-11387 The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation v… Mitigation only Fix from $2,3002026-07-01