Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-41452

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrit…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-39932

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that al…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.2
CVE-2026-39931

OpenEMR through 8.2.0 contains an authenticated SQL injection vulnerability in the backup configuration import feature that allows administrators wit…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.0
CVE-2026-18718

Ghidra contains an arbitrary code execution vulnerability in the Swift demangler analyzer that allows an attacker to execute arbitrary binaries by su…

Patch available
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18610

A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results i…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.8
CVE-2026-18607

A security vulnerability has been detected in Wavlink WN572, WN570H, WN573, WN529, WN530, WN531, WN535, etc. WN529, WN530, WN531, WN535, WN536, WN551…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.8
CVE-2026-18606

A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program …

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.0
CVE-2026-18605

A security flaw has been discovered in CheckMAL AppCheck Pro 3.1.43.10. Affected is an unknown function in the library AppCheckD.sys of the component…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18604

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function DialerActivity of the componen…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18602

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc o…

No fix yet
Fix from $2,300 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-18243

Certain HP DesignJet products may be potentially vulnerable to cross-site scripting (XSS), which may allow unauthenticated HTTP requests to view prin…

No fix yet
Fix from $1,600 2026-08-03
Directory Server MEDIUM 5.4
CVE-2026-18651

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing t…

No fix yet
Fix from $1,600 2026-08-03
\ HIGH 7.5
CVE-2026-18568

XML::Sig versions from 0.29 before 0.72 for Perl allow signature verification bypass because verify returns true when every signature was skipped bef…

Fix: 0.72+
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-18248

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications…

No fix yet
Fix from $2,300 2026-08-03
Unclassified MEDIUM 6.2
CVE-2026-15430

Improper access control in the IRP_MJ_WRITE command interface in Wellbia XIGNCODE3 xhunter2.sys, version 2026.6.1.192, allows a local, unprivileged …

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.8
CVE-2026-67609

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain a privilege escalation vulnerability that allows a…

No fix yet
Fix from $1,950 2026-08-03
\ CRITICAL 9.1
CVE-2026-9487

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve…

Fix: 0.71+
Fix from $2,300 2026-08-03
\ CRITICAL 9.1
CVE-2026-9390

XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions …

Fix: 0.71+
Fix from $2,300 2026-08-03
Unclassified HIGH 7.0
CVE-2026-69097

GitPython before 3.1.53 fails to properly escape section names in git config files, allowing attackers to inject arbitrary configuration directives t…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.8
CVE-2026-69096

OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots containing the ucode docker_rpc.uc RPC backend after the JS/ucode conversion) con…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69095

OpenWrt luci-app-bmx7 before commit 5890760a454dad2cb00389dba2cdc5e779e0ffdd contains a path traversal vulnerability in the bmx7-info CGI script that…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-69092

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echoes unencoded exception messag…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69091

Admidio before 5.0.11 contains an authentication bypass vulnerability in the forum module when configured in login-only mode. The access control logi…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-69089

Grav CMS 2.0.10 contains a path traversal vulnerability in ImageMedium::watermark(), which passes its unsanitized $image argument to RocketTheme\Tool…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.1
CVE-2026-69088

Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint dynamic-field directives bec…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-69087

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, the redirect process action eva…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.7
CVE-2026-69086

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers to constr…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69085

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is …

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69084

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69083

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and…

No fix yet
Fix from $2,300 2026-08-03