Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-57813

Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 10.0
CVE-2026-57811

Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allo…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57770

Deserialization of Untrusted Data vulnerability in ThemeGoods Grand Photography grandphotography allows Object Injection.This issue affects Grand Pho…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57744

Deserialization of Untrusted Data vulnerability in stmcan RT-Theme 18 | Extensions rt18-extensions allows Object Injection.This issue affects RT-Them…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-57739

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AcyMailing Newsletter Team AcyMailing SMTP News…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57738

Deserialization of Untrusted Data vulnerability in axiomthemes 777 triple-seven allows Object Injection.This issue affects 777: from n/a through <= 1…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-57726

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themeum Kirki kirki allows Blind SQL Injection.…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-57724

Deserialization of Untrusted Data vulnerability in Themeum Kirki kirki allows Object Injection.This issue affects Kirki: from n/a through <= 6.0.12.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 10.0
CVE-2026-57719

Unrestricted Upload of File with Dangerous Type vulnerability in CodeRevolution Aimogen Pro aimogen-pro allows Using Malicious Files.This issue affec…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-57714

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LatePoint LatePoint latepoint allows Blind SQL …

No fix yet
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.9
CVE-2026-57710

Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue…

No fix yet
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-57707

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in quantumcloud Simple Business Directory Pro simp…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-57702

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Melograno Venture Studio Amelia ameliabooking a…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.9
CVE-2026-57401

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traver…

Mitigation only
Fix from $2,300 2026-07-13
Gravitino CRITICAL 9.1
CVE-2026-41041

URL path injection via unencoded user-supplied identifiers vulnerability in Apache Gravitino. This issue affects Apache Gravitino: from 1.0.0 before…

Fix: 1.2.1+
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22103

The NPC start endpoint on the web server at port 8090 is vulnerable to command injection.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22102

A POST request sent to a specific webserver endpoint can be used to write to arbitrary file locations. The endpoint accepts the filename parameter in…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.2
CVE-2026-22098

Various sensitive information such as passwords and charging card UIDs are written to log files.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22097

The firmware update mechanism does not include cryptographic signature validation. This allows anyone with access to the firmware update capability t…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22096

The webserver running on port 8090 does not require authentication. This allows for sensitive information leakage such as configured passwords, or up…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.3
CVE-2026-22095

The network diagnosis endpoint on the web server at port 8090 is vulnerable to command injection.

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.5
CVE-2026-22093

The EVbee Service Android app uses TLS encrypted communication (HTTPS), but does not validate the certificate provided by the server. This allows an …

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.2
CVE-2026-13014

A vulnerability in Thales CERT "Suspicious" application =< 1.3.4 allows a remote and unauthenticated attacker to execute arbitrary code and arbitrari…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.6
CVE-2026-14453

This vulnerability is a critical Server-Side Template Injection (SSTI) in Centreon's centreon-open-tickets module that leads to Remote Code Execution…

Mitigation only
Fix from $2,300 2026-07-13
Helix Ultimate CRITICAL 9.1
CVE-2026-57830

Joomla Extension - joomshaper.com - Unauthenticated arbitrary file deletion in Helix Ultimate < 2.2.7 - The Joomla extension Helix Ultimate is vulner…

Fix: after 2.2.6
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-4769

Certain devices in the WAGO System I/O Field series activate an internal diagnostic capability during the initial startup sequence. This functionalit…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.1
CVE-2026-11964

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications…

Mitigation only
Fix from $2,300 2026-07-13
Unclassified CRITICAL 9.8
CVE-2026-15511

A vulnerability was determined in Comfast CF-WR631AX V3 up to 2.7.0.8. Affected by this vulnerability is the function system_wl_upload_pic_file of th…

Mitigation only
Fix from $2,300 2026-07-12
Zephyr CRITICAL 9.8
CVE-2026-10666

parse_ipv4() in subsys/net/ip/utils.c (reached via net_ipaddr_parse() for strings of the form "a.b.c.d:port") copies the port substring into a fixed …

Fix: after 4.4.1
Fix from $2,300 2026-07-12
Flowise CRITICAL 9.8
CVE-2026-56271

Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses weak hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audie…

Fix: 3.1.0+
Fix from $2,300 2026-07-12