Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-65455

Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Intellij Idea CRITICAL 9.8
CVE-2026-64815

In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea CRITICAL 10.0
CVE-2026-64813

In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session

Fix: 2026.2+
Fix from $2,300 2026-07-23
Intellij Idea CRITICAL 10.0
CVE-2026-64812

In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session

Fix: 2026.2+
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-61951

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-61950

Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-61949

Unauthenticated SQL Injection in Bookly <= 27.7 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-61948

Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-59555

Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-59544

Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.9
CVE-2026-59543

Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-59540

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-59526

Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-59525

Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.3
CVE-2026-59514

Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.6
CVE-2026-57784

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.1
CVE-2026-27064

Editor Arbitrary File Upload in Mailster <= 4.1.17 versions.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-65431

Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-64874

Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-64873

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15015

The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T…

Mitigation only
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-15011

The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, an…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.8
CVE-2026-14282

The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to ar…

No fix yet
Fix from $2,300 2026-07-23
Unclassified CRITICAL 9.0
CVE-2026-16723

A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul…

No fix yet
Fix from $2,300 2026-07-23
Platform Security For Java CRITICAL 9.8
CVE-2026-60372

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java CRITICAL 9.9
CVE-2026-60369

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java CRITICAL 9.8
CVE-2026-60367

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Platform Security For Java CRITICAL 10.0
CVE-2026-60366

Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi…

No fix yet
Fix from $2,300 2026-07-22
Unclassified CRITICAL 9.1
CVE-2026-64798

Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-crypto…

No fix yet
Fix from $2,300 2026-07-22
Unclassified CRITICAL 9.8
CVE-2026-64796

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last m…

No fix yet
Fix from $2,300 2026-07-22