Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-47724

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trust…

Patch available
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15981

The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-15630

A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a…

No fix yet
Fix from $2,300 2026-07-23
Moveit Transfer CRITICAL 9.8
CVE-2026-15967

Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before…

Fix: 2025.1.5 / 2026.0.3+
Fix from $2,300 2026-07-23
Moveit Transfer CRITICAL 9.8
CVE-2026-15966

Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before…

Fix: 2025.1.5 / 2026.0.3+
Fix from $2,300 2026-07-23
Moveit Transfer CRITICAL 9.8
CVE-2026-10697

Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.…

Fix: 2025.1.5 / 2026.0.3+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-63359

The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-cra…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.4
CVE-2026-47670

DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-47669

DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-6516

Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65701

SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-65700

h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-47752

Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-47668

DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut…

No fix yet
Fix from $2,300 2026-07-23
Kata Containers CRITICAL 9.9
CVE-2026-44210

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. V…

Fix: 3.31.0+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-65761

Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.2
CVE-2026-65760

Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access ch…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-15617

Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via ca…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-15616

Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized …

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-15612

Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-15611

Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and …

No fix yet
Fix from $2,300 2026-07-23
Standalone Report Designer CRITICAL 9.8
CVE-2026-65689

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that all…

Fix: 14.1.12+
Fix from $2,300 2026-07-23
Standalone Report Designer CRITICAL 9.8
CVE-2026-65688

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allow…

Fix: 14.1.12+
Fix from $2,300 2026-07-23
Standalone Report Designer CRITICAL 9.8
CVE-2026-65687

Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows…

Fix: 14.1.12+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65907

In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible

No fix yet
Fix from $2,300 2026-07-23
Teamcity CRITICAL 10.0
CVE-2026-65906

In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible

Fix: 2025.11.6 / 2026.1.2+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-65606

SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references …

Patch available
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-65605

SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is ren…

Patch available
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-65471

Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-65461

Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.

Mitigation only
Fix from $2,300 2026-07-23