Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-75840 ArcadeDB before 26.8.1 contains an arbitrary file read vulnerability in the GraalVM JavaScript sandbox allowlist enforcement, which uses unescaped re… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-75838 DOMPurify before 3.4.13 contains a cross-site scripting vulnerability in IN_PLACE sanitization where element-removal hooks fail to neutralize detache… No fix yet Fix from $4,0002026-08-18 CRITICAL 9.1 CVE-2026-75837 Grav before 2.0.14 fails to guard the access field in the core group blueprint with the required security@: admin.super restriction. A delegated admi… No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-75836 The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in M… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-75834 Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/src/Grav/Common/Security.php). … No fix yet Fix from $4,0002026-08-18 HIGH 7.1 CVE-2026-75830 grav-plugin-api (getgrav/grav-plugin-api) versions >= 1.0.0-beta.10 and <= 1.0.14 contain a path traversal vulnerability in the PagesController::batc… No fix yet Fix from $4,9002026-08-18 HIGH 8.1 CVE-2026-75829 grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission … No fix yet Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-75828 Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value… No fix yet Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-75827 Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-75107 Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.9 CVE-2026-74907 Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di… No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-74906 SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi… No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-74905 SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-74904 SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE… No fix yet Fix from $4,9002026-08-18 HIGH 8.6 CVE-2026-74902 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.7 CVE-2026-5224 Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve… No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-15585 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.3 CVE-2026-75626 SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject … No fix yet Fix from $5,7502026-08-18 MEDIUM 5.3 CVE-2026-19608 A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-19447 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO… No fix yet Fix from $4,0002026-08-18 CRITICAL 9.8 CVE-2026-34884 SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M… No fix yet Fix from $5,7502026-08-18 HIGH 8.1 CVE-2026-15371 Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked … No fix yet Fix from $4,9002026-08-18 HIGH 7.2 CVE-2026-75091 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-15748 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl… No fix yet Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-11801 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-75094 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid… No fix yet Fix from $5,7502026-08-18 HIGH 7.3 CVE-2026-75089 A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75088 A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-75087 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-75086 A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.… No fix yet Fix from $4,0002026-08-18