Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-15721

Cleartext storage of sensitive information vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows S…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-14804

Use of hard-coded cryptographic key vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources allows Read Sen…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-14175

Unrestricted upload of file with dangerous type vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human Resources all…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-18754

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private k…

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-18753

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private k…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-64564

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_a…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.3
CVE-2026-15958

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions …

No fix yet
Fix from $2,300 2026-08-04
Edge Chromium CRITICAL 9.6
CVE-2026-66321

Access of resource using incompatible type ('type confusion') in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over…

Fix: 151.0.4129.59+
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-18686

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the …

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-18685

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the com…

No fix yet
Fix from $2,300 2026-08-04
Campaign CRITICAL 9.8
CVE-2026-48333

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could exp…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Campaign CRITICAL 10.0
CVE-2026-48331

Adobe Campaign Classic (ACC) is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. Exploitatio…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Campaign CRITICAL 10.0
CVE-2026-48330

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Campaign CRITICAL 9.9
CVE-2026-48326

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Campaign CRITICAL 10.0
CVE-2026-48323

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result …

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Campaign CRITICAL 9.6
CVE-2026-48317

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability t…

Fix: after 7.4.2
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18684

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the compo…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.6
CVE-2026-18667

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sens…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.2
CVE-2026-46713

Misskey is an open source, federated social media platform. Versions 12.37.0 and later, but prior to 2026.5.4, contain a vulnerability in the JSON-LD…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-69240

Sequelize is a Node.js ORM tool. Prior to 6.37.4, SQL injection is possible with strings only if dialect is set to oracle. The escape function define…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-52102

An OS command injection vulnerability in the openmediavault-md plugin of OpenMediaVault v8.0.4-1 allows attackers to execute arbitrary commands as ro…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-51775

SQL injection vulnerability in Fastadmin v.1.6.1.20250430 allows an attacker to exectue arbitrary code via the application/common/controller/Backend.…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-51190

The "s init" command in Serverless-Devs @serverless-devs/s <= 3.1.11 passes unsanitized user input to child_process.spawn() with shell: true. A URL e…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-48063

Baileys is a cocket-based TS/JavaScript API for WhatsApp Web. In versions prior to both 6.7.22 and 7.0.0-rc12, any Baileys session can be sent a mal…

Patch available
Fix from $2,300 2026-08-03
Nifi CRITICAL 9.1
CVE-2026-68980

Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and deleting Assets associated with Parameter Contexts through the REST API. The framewor…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Nifi CRITICAL 9.8
CVE-2026-68979

Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update REST API method that does not enforce authorization checking on components refer…

Fix: 2.11.0+
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-48031

go-base is a Go RESTful API Boilerplate template with JWT Authentication, backed by PostgreSQL. In versions prior to 2026-05-18, the JWT signing secr…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-38447

osTicket 1.18.3 generates API keys using a predictable construction based on MD5 hashing. The use of MD5, combined with predictable inputs such as th…

Patch available
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18616

A vulnerability was identified in GL-iNet GL-MT3000 up to 4.4.5. The impacted element is the function server.set_peer of the file /cgi-bin/glc of the…

No fix yet
Fix from $2,300 2026-08-03