Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2025-69935

CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69934

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69933

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-69930

CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1.

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 6.1
CVE-2025-65342

code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field.

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.1
CVE-2025-65341

Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php.

No fix yet
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.8
CVE-2025-65336

Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php.

Mitigation only
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67594

Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes…

No fix yet
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.7
CVE-2026-67550

re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a…

Patch available
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.4
CVE-2026-67530

WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its…

Patch available
Fix from $1,600 2026-07-30
Unclassified HIGH 7.6
CVE-2026-67527

OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and al…

Patch available
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-67208

Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by …

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.8
CVE-2026-67207

Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users…

Mitigation only
Fix from $1,950 2026-07-30
Unclassified HIGH 8.8
CVE-2026-67206

Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr…

No fix yet
Fix from $1,950 2026-07-30
Tika CRITICAL 9.8
CVE-2026-66756

Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a…

No fix yet
Fix from $2,300 2026-07-30
Tika HIGH 7.5
CVE-2026-66755

Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker…

Fix: 3.3.2+
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.6
CVE-2026-65835

Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour…

No fix yet
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.8
CVE-2026-65834

Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex a…

No fix yet
Fix from $1,600 2026-07-30
Langflow CRITICAL 9.9
CVE-2026-12946

IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.10.1+
Fix from $2,300 2026-07-30
Websphere Application Server HIGH 8.5
CVE-2026-11536

IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector.

Fix: 8.5.5.29 / 9.0.5.28+
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.1
CVE-2025-51684

CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessa…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 8.8
CVE-2026-66416

Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf …

Patch available
Fix from $1,950 2026-07-30
Unclassified HIGH 8.5
CVE-2026-66415

Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal res…

Patch available
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.5
CVE-2026-66066

Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di…

Patch available
Fix from $2,300 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-64870

MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied downloa…

Patch available
Fix from $1,600 2026-07-30
Unclassified HIGH 7.5
CVE-2026-61536

Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered…

No fix yet
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.9
CVE-2026-59881

AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames…

Patch available
Fix from $1,600 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-51272

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. …

No fix yet
Fix from $2,300 2026-07-30
Unclassified CRITICAL 9.3
CVE-2026-48499

Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut…

Patch available
Fix from $2,300 2026-07-30
Amplify Codegen Ui HIGH 8.8
CVE-2026-18245

Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar…

Fix: 2.20.6+
Fix from $1,950 2026-07-30