Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-36327 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could allow an authenticated user to bypass security controls and perform unauthorized actio… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2025-36323 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to em… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.7 CVE-2025-36321 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which w… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.4 CVE-2025-36320 IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated use… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2025-12530 IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through Patch 1 transmits data in clear text that could allow an attacker to obtain sensitiv… Watsonx.data Intelligence Mitigation only Fix from $1,6002026-06-30 HIGH 7.2 CVE-2026-10513 The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 via parser-derived 'avatar' an… Mitigation only Fix from $1,9502026-06-30 HIGH 7.3 CVE-2026-8864 The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been released to mitig… Mitigation only Fix from $1,9502026-06-30 HIGH 8.1 CVE-2026-58377 JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, up… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-58375 JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so Ji… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-49451 The OpenAPI.NET SDK contains a useful object model for OpenAPI documents in .NET along with common serializers to extract raw OpenAPI JSON and YAML d… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.3 CVE-2026-48315 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-30 MEDIUM 6.5 CVE-2026-48314 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.3 CVE-2026-48313 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $2,3002026-06-30 HIGH 8.8 CVE-2026-48307 ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this … Coldfusion Mitigation only Fix from $1,9502026-06-30 HIGH 8.6 CVE-2026-48285 ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security fe… Coldfusion Mitigation only Fix from $1,9502026-06-30 CRITICAL 10.0 CVE-2026-48283 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48281 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48277 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execut… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48276EPSS 5% ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in… Coldfusion Mitigation only Fix from $2,3002026-06-30 CRITICAL 10.0 CVE-2026-48282 KEVEPSS 99% ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vul… Coldfusion Mitigation only Fix from $2,3002026-06-30 MEDIUM 5.3 CVE-2026-44948 A path traversal vulnerability was found in Fleet's ImageScan subsystem in Rancher Fleet 0.12.0 up to 0.12.16, 0.13.0 up to 0.13.12, 0.14.0 up to 0.1… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.4 CVE-2026-48192 A vulnerability has been identified in Mendix Studio Pro 10.11 (All versions), Mendix Studio Pro 10.12 (All versions), Mendix Studio Pro 10.13 (All v… Mitigation only Fix from $1,6002026-06-30 HIGH 7.0 CVE-2026-44949 A Rancher FleetWorkspace admission path allowed side effects to occur in the Rancher webhook handler for versions 0.7.0 up to 0.7.10, 0.8.0 up to 0.… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.9 CVE-2026-44947 A missing clean-up in the legacy Project Role Template Binding (PRTB) reconciler in Rancher versions 2.13.0 up to 2.13.7 and 2.14.0 up to 2.14.3 all… Mitigation only Fix from $1,6002026-06-30 HIGH 8.8 CVE-2026-27957 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, an authenticated command… Mitigation only Fix from $1,9502026-06-30 MEDIUM 6.6 CVE-2026-27955 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the executeInDocker() he… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.0 CVE-2026-27883 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the `GET /api/v1/deploym… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.0 CVE-2026-27881 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, `GET /api/v1/deployments… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.9 CVE-2026-35098 KTM System e-BOK does not implement any limit or timeout on consecutive login attempts, allowing an attacker to perform unlimited authentication requ… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.9 CVE-2026-35097 KTM System e-BOK enforces a maximum password length of six numeric digits and does not permit the use of any alphabetic, special, or extended charact… Mitigation only Fix from $1,6002026-06-30