Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-63233

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall an…

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63232

A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcem…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, …

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO …

Mitigation only
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP we…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which …

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-18072

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a H…

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-64863

goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOV…

Patch available
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.1
CVE-2026-62325

goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handl…

Patch available
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-54658

Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl…

Patch available
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive …

Mitigation only
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14976

IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e…

Fix: 26.0.0.9+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14974

IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Aspera CRITICAL 9.3
CVE-2026-14973

IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination.

Fix: after 1.0.19
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14512

IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac…

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-14446

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console.

Fix: 8.5.5.30 / 9.0.5.28+
Fix from $2,300 2026-07-28
Websphere Application Server CRITICAL 9.8
CVE-2026-16184

IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request.

Fix: 8.5.5.31 / 9.0.5.29+
Fix from $2,300 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-16498

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode …

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51268

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untr…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.6
CVE-2026-51271

In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The fun…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51267

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application s…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51266

schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynam…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51263

schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON r…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.2
CVE-2026-67174

Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHT…

Patch available
Fix from $2,300 2026-07-28
Axis2\/java CRITICAL 9.8
CVE-2026-66713

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0…

Fix: 2.0.1+
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51261

Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5 creates a race condition between concurrent tasks. The…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-51260

Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code cop…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51259

Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subs…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.8
CVE-2026-51252

schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on at…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-65880

Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code exec…

No fix yet
Fix from $2,300 2026-07-28