Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Cjson MEDIUM 5.3
CVE-2026-67217

cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing…

Fix: after 1.7.19
Fix from $1,600 2026-07-29
Cjson HIGH 7.5
CVE-2026-67216

cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each …

Fix: after 1.7.19
Fix from $1,950 2026-07-29
Cjson HIGH 7.5
CVE-2026-67215

cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUt…

Fix: after 1.7.19
Fix from $1,950 2026-07-29
Nanoid HIGH 7.5
CVE-2026-67214

nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-s…

Fix: 5.1.16+
Fix from $1,950 2026-07-29
Gridbox MEDIUM 5.3
CVE-2026-66489

Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Gridbox MEDIUM 5.3
CVE-2026-66488

Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Nanoid HIGH 7.5
CVE-2026-67213

nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a …

Fix: 3.3.17 / 5.1.6+
Fix from $1,950 2026-07-29
Gridbox MEDIUM 6.1
CVE-2026-66490

Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65890

Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Gridbox HIGH 7.5
CVE-2026-65889

Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet…

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Unclassified HIGH 8.7
CVE-2026-55995

A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 5…

Patch available
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.5
CVE-2026-16751

Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured…

No fix yet
Fix from $1,600 2026-07-29
Fastify\/forwarded MEDIUM 5.3
CVE-2026-18174

@fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma se…

Fix: 3.0.2+
Fix from $1,600 2026-07-29
Ro Csvi HIGH 8.8
CVE-2026-65944

Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0

Fix: 9.11.0+
Fix from $1,950 2026-07-29
Ro Csvi MEDIUM 6.1
CVE-2026-65946

Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0

Fix: 9.11.0+
Fix from $1,600 2026-07-29
Ro Csvi HIGH 7.5
CVE-2026-65943

Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0

Fix: 9.11.0+
Fix from $1,950 2026-07-29
Jce MEDIUM 6.5
CVE-2026-65891

Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE…

Fix: 2.20.2+
Fix from $1,600 2026-07-29
Gridbox HIGH 8.8
CVE-2026-65885

Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo…

Fix: 2.20.2+
Fix from $1,950 2026-07-29
Gridbox CRITICAL 9.8
CVE-2026-65884

Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una…

Fix: 2.20.2+
Fix from $2,300 2026-07-29
Unclassified HIGH 7.1
CVE-2026-50641

Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.5
CVE-2026-44944

An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects…

Patch available
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.9
CVE-2026-44943

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create…

Patch available
Fix from $1,600 2026-07-29
Unclassified MEDIUM 5.1
CVE-2026-33385

A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.7
CVE-2026-14354

CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, po…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 8.4
CVE-2026-12927

CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.3
CVE-2026-0667

CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of …

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.8
CVE-2026-14270

The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-8791

The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-7436

The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_bes…

No fix yet
Fix from $1,600 2026-07-29
Aimy Captcha Less Form Guard CRITICAL 9.8
CVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o…

Fix: after 20.0
Fix from $2,300 2026-07-29