Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-6382

The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.8
CVE-2026-14808

Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to …

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.8
CVE-2026-14807

ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view applicat…

Mitigation only
Fix from $2,300 2026-07-06
Unclassified CRITICAL 9.2
CVE-2026-59509

An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate reque…

Patch available
Fix from $2,300 2026-07-05
Fickling CRITICAL 9.8
CVE-2026-14535

In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(n…

Fix: after 0.1.11
Fix from $2,300 2026-07-04
Unclassified CRITICAL 9.6
CVE-2026-58426

Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-58422

Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

Patch available
Fix from $2,300 2026-07-03
Edge Chromium CRITICAL 10.0
CVE-2026-57983

Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

Fix: 150.0.4078.48+
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-27780

Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass b…

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-26292

Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration tran…

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-26247

Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the…

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-26232

Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange.

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-25718

Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through s…

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.6
CVE-2026-22874

Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering.

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-20706

Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint.

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-22547

Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or …

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-20896

Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user w…

Patch available
Fix from $2,300 2026-07-03
Keras CRITICAL 9.8
CVE-2026-12481

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-56015

Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the tr…

Patch available
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-4321

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertisi…

Mitigation only
Fix from $2,300 2026-07-03
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-14544

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attac…

Mitigation only
Fix from $2,300 2026-07-03
Curl CRITICAL 9.8
CVE-2026-9079

libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get …

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.1
CVE-2026-8927

When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.1
CVE-2026-8926

When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.8
CVE-2026-8925

The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.1
CVE-2026-8924

A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.8
CVE-2026-11856

Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a diff…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.1
CVE-2026-11564

libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle th…

Fix: 8.21.0+
Fix from $2,300 2026-07-03
Curl CRITICAL 9.8
CVE-2026-10536

A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR…

Fix: 8.21.0+
Fix from $2,300 2026-07-03