Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-71248

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f…

Patch available
Fix from $2,300 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71247

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.1
CVE-2026-71245

Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with Inp…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-71244

Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, ac…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71243

The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd =…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.3
CVE-2026-71242

Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71241

Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required dec…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-71239

DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, …

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71238

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71237

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.7
CVE-2026-71236

Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPuri…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-71235

Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. T…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-71234

Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) a…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.7
CVE-2026-71233

InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (r…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-71232

MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex…

Patch available
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71231

IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-66747

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o…

No fix yet
Fix from $2,300 2026-08-05
Theia HIGH 8.8
CVE-2026-60009

In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Theia MEDIUM 6.5
CVE-2026-14574

In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference va…

Fix: 1.74.0+
Fix from $1,600 2026-08-05
Accessibility Tools Framework MEDIUM 5.5
CVE-2026-14304

In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe…

Fix: 3.2.0+
Fix from $1,600 2026-08-05
Theia HIGH 7.5
CVE-2026-12609

In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e…

Fix: 1.74.0+
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-44945

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w…

Patch available
Fix from $2,300 2026-08-05
Unclassified HIGH 7.3
CVE-2026-25703

NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing …

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.9
CVE-2026-0931

Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.0
CVE-2026-10090

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-10059

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp…

No fix yet
Fix from $2,300 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-7726

The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::tem…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-7693

The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient san…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-7520

The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `si…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-7444

The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is du…

No fix yet
Fix from $1,950 2026-08-05