Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-75829 grav-plugin-api versions before 1.0.15 fail to validate Twig content in the translate() endpoint, allowing attackers with api.pages.write permission … No fix yet Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-75828 Grav before 2.0.15 contains a stored cross-site scripting vulnerability in the detectXss() function where unpaired quotes in unquoted attribute value… No fix yet Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-75827 Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete deny… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.4 CVE-2026-75107 Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, section text, and select option la… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.9 CVE-2026-74907 Grav before 2.0.15 contains a path traversal vulnerability in the static asset server within index.php that uses string prefix matching instead of di… No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-74906 SiYuan before v3.7.4 contains an incorrect authorization vulnerability in eight publish-mode reader-facing endpoints that filter results using the vi… No fix yet Fix from $4,9002026-08-18 HIGH 7.1 CVE-2026-74905 SiYuan before v3.7.4 contains a server-side request forgery (SSRF) vulnerability in the isPrivateIP function in kernel/util/net.go, used by SSRFSafeD… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-74904 SiYuan before v3.7.4 is missing authorization checks in 17 block metadata/content endpoints in kernel/api/block.go (including getRefText, checkBlockE… No fix yet Fix from $4,9002026-08-18 HIGH 8.6 CVE-2026-74902 SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to escape filenames before inserting… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.7 CVE-2026-5224 Cleartext storage of sensitive information vulnerability in Kriptok Crypto and Information Technologies Industry Trade Inc. Cryptosim allows Retrieve… No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-15585 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AKIN Software Computer Import Export Industry and Tra… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.3 CVE-2026-75626 SpiderFoot fails to HTML-escape correlation titles built from external scan data sources including server banners and metadata. Attackers can inject … No fix yet Fix from $5,7502026-08-18 MEDIUM 5.3 CVE-2026-19608 A flaw was found in the group policy provider of Keycloak authorization services, which is used to manage fine-grained access control to resources. T… No fix yet Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-19447 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informatics Services Trade Inc. FileO… No fix yet Fix from $4,0002026-08-18 CRITICAL 9.8 CVE-2026-34884 SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issue affects Apache SkyWalking M… No fix yet Fix from $5,7502026-08-18 HIGH 8.1 CVE-2026-15371 Velociraptor's web GUI allows specifying a custom type for columns in tables. The URL type takes the cell value and forms a URL which can be clicked … No fix yet Fix from $4,9002026-08-18 HIGH 7.2 CVE-2026-75091 The Quill Forms | Conversational Multi Step Forms, Surveys & quizzes plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all version… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-15748 The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upl… No fix yet Fix from $5,7502026-08-18 HIGH 7.5 CVE-2026-11801 The WPAdverts – Classifieds Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.3.2. This is du… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.1 CVE-2026-75094 A flaw has been found in COMFAST CF-N1-S 2.6.0.1. This impacts the function sub_44B438 of the file /cgi-bin/mbox-config?method=SET&section=ptest_ssid… No fix yet Fix from $5,7502026-08-18 HIGH 7.3 CVE-2026-75089 A weakness has been identified in PHPGurukul Complaint Management System 1.0. Affected by this issue is some unknown functionality of the file user/c… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.3 CVE-2026-75088 A vulnerability was determined in itsourcecode Hospital Management System 1.0. This impacts an unknown function of the file /viewbilling.php. Executi… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-75087 A vulnerability was found in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /viewdepartment.php. Performin… No fix yet Fix from $4,0002026-08-18 MEDIUM 6.3 CVE-2026-75086 A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /viewroom.php.… No fix yet Fix from $4,0002026-08-18 HIGH 7.3 CVE-2026-75080 A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This issue affects some unknown processing of the… No fix yet Fix from $4,9002026-08-18 HIGH 7.3 CVE-2026-75079 A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /edit_sub… No fix yet Fix from $4,9002026-08-18 HIGH 7.8 CVE-2026-67961 An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution. No fix yet Fix from $4,9002026-08-17 CRITICAL 9.8 CVE-2026-67919 An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri method, and DefaultPluginAppli… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-42164 Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a certain way that allows it to rec… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.1 CVE-2026-42162 Mahara before 25.04.5 and 26.04.0 is vulnerable to artefacts being accessible to others under certain circumstances when the file path to an artefact… No fix yet Fix from $5,7502026-08-17