Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-57873 An unauthenticated NULL pointer dereference vulnerability exists in IEEE8021x_upload.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. Th… Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-57872 An unauthenticated directory traversal vulnerability exists in get_fcont.cgi in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerabil… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-8380 The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, a… Mitigation only Fix from $1,6002026-06-26 HIGH 7.7 CVE-2026-10835 The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not properly sanitise and escape a parameter passed to one of its AJAX actions before us… Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-10823 The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and does not validate a user-suppli… Mitigation only Fix from $1,9502026-06-26 MEDIUM 5.3 CVE-2025-10268 The Printcart Web to Print Product Designer for WooCommerce WordPress plugin through 2.4.8 is vulnerable to path traversal which makes it possible fo… Mitigation only Fix from $1,6002026-06-26 HIGH 8.5 CVE-2026-8797 An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-13226 The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'after' parameter in … Mitigation only Fix from $1,6002026-06-26 HIGH 8.1 CVE-2026-9222 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend servic… Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-9221 The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating co… Mitigation only Fix from $1,9502026-06-26 HIGH 7.5 CVE-2026-9220 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardco… Mitigation only Fix from $1,9502026-06-26 MEDIUM 6.5 CVE-2026-9219 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment s… Mitigation only Fix from $1,6002026-06-26 MEDIUM 6.9 CVE-2026-43920 FOSSBilling is a free, open-source billing and client management system. In versions 0.5.4 through 0.7.2, the /run-patcher maintenance endpoint in FO… Mitigation only Fix from $1,6002026-06-26 HIGH 7.3 CVE-2026-54479 The WebSocket backend uses charging station identifiers to uniquely associate sessions but allows multiple endpoints to connect using the same sessio… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-50176 The WebSocket Application Programming Interface lacks restrictions on the number of authentication requests. This absence of rate limiting may allow … Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-44622 Charging station authentication identifiers are publicly accessible via web-based mapping platforms. Mitigation only Fix from $1,6002026-06-25 CRITICAL 9.4 CVE-2026-40702 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit th… Mitigation only Fix from $2,3002026-06-25 HIGH 8.1 CVE-2026-22879 vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability Mitigation only Fix from $1,9502026-06-25 HIGH 8.1 CVE-2025-71340 picklescan through 0.0.26 fails to detect malicious pickle files that invoke idlelib.pyshell.ModifiedInterpreter.runcode in __reduce__ methods. Attac… Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.1 CVE-2025-71327 Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to… Flowise No fix yet Fix from $2,3002026-06-25 HIGH 7.5 CVE-2021-47987 Parse Server before 4.10.0 was affected by a supply chain incident in which incorrect version tags were pushed to the official repository pointing to… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2021-47986 Parse Server before 4.10.0 contains a supply chain vulnerability where incorrect version tags were pushed to the repository linking to unreviewed cod… Parse Server Mitigation only Fix from $1,9502026-06-25 CRITICAL 9.1 CVE-2026-56445 The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitizatio… Mitigation only Fix from $2,3002026-06-25 HIGH 7.5 CVE-2026-38640 A reachable unwrap in the __assert_fail function (/assert/mod.rs) of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a c… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-38637 An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted in… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-37452 Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAP… Mitigation only Fix from $1,9502026-06-25 HIGH 8.2 CVE-2026-12473 Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global aut… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-46602 The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to c… Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-46601 The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size. Mitigation only Fix from $1,9502026-06-25 HIGH 7.7 CVE-2026-37149 GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in… Mitigation only Fix from $1,9502026-06-25