Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Azure Cosmos Db CRITICAL 10.0
CVE-2026-66803

Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.3
CVE-2026-66418

OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML …

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 6.1
CVE-2026-61526

AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.…

Patch available
Fix from $1,600 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-55777

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the pa…

Patch available
Fix from $1,600 2026-07-30
Unclassified HIGH 8.7
CVE-2026-55768

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11…

Patch available
Fix from $1,950 2026-07-30
Unclassified HIGH 7.1
CVE-2026-54715

GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, pa…

Patch available
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.1
CVE-2026-52539

Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back…

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-35847

An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69931

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69947

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69941

SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69938

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69937

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69936

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69935

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69934

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69933

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69930

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 6.1
CVE-2025-65342

code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2025-65341

Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.

No fix yet
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-65336

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67594

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes…

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.7
CVE-2026-67550

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a…

Patch available
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.4
CVE-2026-67530

WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its…

Patch available
Fix from $1,600 2026-07-30
Unclassified HIGH 7.6
CVE-2026-67527

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and al…

Patch available
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67208

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by …

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.8
CVE-2026-67207

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users…

Mitigation only
Fix from $1,950 2026-07-30
Unclassified HIGH 8.8
CVE-2026-67206

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr…

No fix yet
Fix from $1,950 2026-07-30
Tika CRITICAL 9.8
CVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a…

No fix yet
Fix from $2,300 2026-07-30
Tika HIGH 7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker…

Fix: 3.3.2+
Fix from $1,950 2026-07-30