Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-65701

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-65700

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,…

No fix yet
Fix from $2,300 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-47769

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Prior to commit 7f19b52280f414f…

Patch available
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.5
CVE-2026-47755

ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prior to version 26.05, low-privileged auth…

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-47752

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.7
CVE-2026-47743

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, three related defects on admin Livewire components allowed data tampering, sensitive da…

Patch available
Fix from $1,950 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-47668

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut…

No fix yet
Fix from $2,300 2026-07-23
Kata Containers CRITICAL 9.9
CVE-2026-44210

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. V…

Fix: 3.31.0+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-65761

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.2
CVE-2026-65760

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access ch…

No fix yet
Fix from $2,300 2026-07-23
Unclassified HIGH 8.7
CVE-2026-65759

Joomla Extension - joomshaper.com - unauthenticated payment/order forgery in Easy Store extension 1.0.0-2.0.1 - Critical order and payment informatio…

No fix yet
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-65698

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjacent attackers to read arbitrar…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.1
CVE-2026-65697

Fathom Lite through 1.3.1 contains a stored cross-site scripting vulnerability in the analytics collection endpoint that allows unauthenticated attac…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-65696

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscription API that allows authenti…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 6.8
CVE-2026-65695

Office-Word-MCP-Server through 1.1.11 contains a path traversal vulnerability in its document tools that allows attackers who can influence the filen…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.5
CVE-2026-44909

Proxygen lacked a generalized slow-consumer detection mechanism in its core HTTP session layer. A remote, unauthenticated attacker could exploit HTTP…

Patch available
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-16768

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined palette range, an out-of-bounds r…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 8.8
CVE-2026-65917

CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's …

Patch available
Fix from $1,950 2026-07-23
Unclassified HIGH 8.1
CVE-2026-65916

CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows aut…

Patch available
Fix from $1,950 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48539

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report configuration that allows authent…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48538

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configuration that allows authenticated…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48537

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configuration that allows authenticated …

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48536

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuration that allows authenticated a…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48535

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configuration that allows authenticated …

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48534

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that allows authenticated attackers t…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48532

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy configuration that allows authent…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48531

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration that allows authenticated attack…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.4
CVE-2026-48530

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration that allows authenticated at…

No fix yet
Fix from $1,600 2026-07-23
Unclassified HIGH 7.0
CVE-2026-16584

Improper handling of an initialization failure in AWS API MCP Server from 0.2.13 through 1.3.46 might allow an actor to bypass the user-configured se…

No fix yet
Fix from $1,950 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-15617

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via ca…

No fix yet
Fix from $2,300 2026-07-23