Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.1 CVE-2026-35096 KTM System e-BOK is vulnerable to Cross‑Site Request Forgery (CSRF) in both the email-change and password-change functionalities. An attacker can cra… Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.8 CVE-2026-14241 Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of… Firefox Mitigation only Fix from $2,3002026-06-30 MEDIUM 5.9 CVE-2026-14178 openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fmt_nls() 会将 nls_fmt_str 保存到 u_sess->parser_cxt.nls_fmt_str。在 seqscan + s… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.1 CVE-2026-8403 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Eksagate Electronic Engineering and Computer In… Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-4629 A flaw was found in Keycloak. A highly privileged user with `manage-clients` permission can exploit this vulnerability by injecting a hardcoded role … Build Of Keycloak No fix yet Fix from $1,6002026-06-30 MEDIUM 6.5 CVE-2026-12388 A flaw was found in the Identity Provider (IdP) mapper component of Keycloak, which is used to manage how user information from external services is … Build Of Keycloak Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.8 CVE-2026-8402 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Eksagate Electronic Engineering and Computer In… Mitigation only Fix from $2,3002026-06-30 MEDIUM 5.9 CVE-2026-57082 Net::BitTorrent versions before 2.1.0 for Perl generate the MSE Diffie-Hellman private key with a non-cryptographic PRNG. The MSE (Message Stream En… Mitigation only Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-57081 Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via deeply nested bencoded input. bdecode recurses once per nested li… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-57080 Net::BitTorrent versions through 2.1.0 for Perl allow remote memory exhaustion via an uncapped peer-wire message-length prefix. The peer-wire framin… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.3 CVE-2026-57079 Net::BitTorrent versions before 2.1.0 for Perl write files outside the download directory via path traversal in peer-supplied metadata. Net::BitTorr… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.9 CVE-2026-53692 Redeight CMS version 1.0 uses the MD5 algorithm without a salt to store user passwords. Because MD5 is a cryptographically broken algorithm and lacks… Mitigation only Fix from $1,6002026-06-30 HIGH 8.6 CVE-2026-53691 An Unrestricted File Upload vulnerability in Redeight CMS version 1.0 allows authenticated attackers to achieve Remote Code Execution via the POST "/… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.3 CVE-2026-53690 An SQL Injection vulnerability exists in Redeight CMS version 1.0 via the "userEmail" parameter in the POST "/admin/index.php" login endpoint. The ap… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-14162 Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a… Mitigation only Fix from $2,3002026-06-30 HIGH 7.5 CVE-2026-14161 Hospital Quening Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a… Mitigation only Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-50750 Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Following the fix for CVE-2026-4… Activemq Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.8 CVE-2026-9711 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter… Mitigation only Fix from $2,3002026-06-30 HIGH 7.2 CVE-2026-8141 The Ajax Load More - Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'taxonomy_include_children' parameter in all v… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.1 CVE-2026-6954 Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or i… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.1 CVE-2026-6953 HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML … Mitigation only Fix from $1,6002026-06-30 MEDIUM 6.4 CVE-2026-12610 A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory … Enterprise Linux Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.3 CVE-2026-12076 Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to e… Mitigation only Fix from $2,3002026-06-30 HIGH 7.0 CVE-2026-10763 PROMOD V is using insecure HTTP communication instead of HTTPS. The vulnerability is due to the lack of HTTPS support from 3rd party Digipede server. Mitigation only Fix from $1,9502026-06-30 HIGH 8.4 CVE-2026-12578 The affected product is vulnerable to a deserialization of untrusted data, which may allow an attacker to execute arbitrary code. No fix yet Fix from $1,9502026-06-30 HIGH 7.2 CVE-2026-56808 DGM3103SCT provided by AVTECH Security Corporation contains an OS command injection vulnerability, which may lead to arbitrary command execution with… Mitigation only Fix from $1,9502026-06-30 HIGH 7.8 CVE-2026-56137 RPG MAKER MV and MZ provided by Gotcha Gotcha Games Inc. contain an OS command injection vulnerability. If a user loads a specially crafted save-file… Mitigation only Fix from $1,9502026-06-30 CRITICAL 9.3 CVE-2026-12819 Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated… Mitigation only Fix from $2,3002026-06-30 MEDIUM 6.1 CVE-2026-56809 Multiple laser printers and MFPs (multifunction printers) which implement Ricoh Web Image Monitor contain a reflected cross-site scripting vulnerabil… Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.3 CVE-2026-12818 Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP … Mitigation only Fix from $2,3002026-06-30