Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-56823 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to , the `POST /api/… Mitigation only Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-56663 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authen… Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-55677 Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.0 CVE-2026-48529 GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCac… Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2026-11779 An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2025-32423 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is … Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2025-32394 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.32, there is … Mitigation only Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-0828 Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL … Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.8 CVE-2026-0685 Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2025-11919 The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/U… Mitigation only Fix from $2,3002026-06-26 MEDIUM 5.6 CVE-2023-20572 An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication… Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.8 CVE-2026-9699 Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user … Mitigation only Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-57667 Sales Representative SQL Injection in Groundhogg <= 4.5 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.3 CVE-2026-57665 Unauthenticated Insecure Direct Object References (IDOR) in GravityView <= 3.0.0 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-57663 Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions. Mitigation only Fix from $1,9502026-06-26 HIGH 8.5 CVE-2026-57662 Contributor SQL Injection in Contest Gallery <= 30.0.0 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.4 CVE-2026-57661 Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 5.3 CVE-2026-57660 Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 8.8 CVE-2026-57659 Unauthenticated Cross Site Request Forgery (CSRF) in Paid Memberships Pro - Add Member From Admin <= 0.7.2 versions. Mitigation only Fix from $1,9502026-06-26 CRITICAL 9.1 CVE-2026-57658 Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. Mitigation only Fix from $2,3002026-06-26 MEDIUM 5.9 CVE-2026-57656 Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions. No fix yet Fix from $1,6002026-06-26 HIGH 8.2 CVE-2026-57655 Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-57654 Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-57653 Contributor SQL Injection in WP Job Portal <= 2.5.2 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.3 CVE-2026-57652 Unauthenticated Insecure Direct Object References (IDOR) in JS Help Desk <= 3.1.0 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-57651 Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions. Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.5 CVE-2026-57650 Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions. No fix yet Fix from $1,6002026-06-26 HIGH 7.5 CVE-2026-57647 Contributor Local File Inclusion in Panorama Viewer – 360 Degree Image + Video Viewer <= 1.6.1 versions. Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.4 CVE-2026-57646 Subscriber Insecure Direct Object References (IDOR) in Majestic Support <= 1.1.7 versions. Mitigation only Fix from $1,6002026-06-26 HIGH 8.1 CVE-2026-57645 newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions. Mitigation only Fix from $1,9502026-06-26