Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-9725

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified CRITICAL 10.0
CVE-2026-13768

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic…

Mitigation only
Fix from $2,300 2026-07-03
365 Copilot CRITICAL 9.3
CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-07-02
Azure Synapse CRITICAL 9.8
CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.4
CVE-2026-52830

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se…

No fix yet
Fix from $2,300 2026-07-02
Arduplane CRITICAL 9.1
CVE-2026-38971

ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle…

Fix: after 4.6.3
Fix from $2,300 2026-07-02
Ntopng CRITICAL 9.8
CVE-2026-38968

ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cp…

Fix: after 6.6
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.1
CVE-2026-59099

Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversati…

Patch available
Fix from $2,300 2026-07-02
Juicefs CRITICAL 9.8
CVE-2026-59092

JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to acces…

Fix: after 1.3.1
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-58466

AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the adminis…

Patch available
Fix from $2,300 2026-07-02
Rancher Fleet CRITICAL 9.9
CVE-2026-44935

Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and …

Fix: 0.12.15 / 0.13.11+
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2024-14037

Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading …

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2022-50973

Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-58455EPSS 8%

Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell comm…

Patch available
Fix from $2,300 2026-07-02
Unclassified CRITICAL 10.0
CVE-2026-56004

A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _…

Patch available
Fix from $2,300 2026-07-02
Unifi Connect CRITICAL 9.8
CVE-2026-55116

A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in…

Fix: 3.4.20+
Fix from $2,300 2026-07-02
Unifi Protect CRITICAL 9.9
CVE-2026-55115

A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es…

Fix: 7.1.83+
Fix from $2,300 2026-07-02
Unifi Protect CRITICAL 9.8
CVE-2026-54408

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth…

Fix: 7.1.83+
Fix from $2,300 2026-07-02
Unifi Access CRITICAL 9.1
CVE-2026-54400

A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Applica…

Fix: 4.2.29+
Fix from $2,300 2026-07-02
Unifi Access CRITICAL 9.9
CVE-2026-50748

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Applic…

Fix: 4.2.29+
Fix from $2,300 2026-07-02
Unifi Talk Application CRITICAL 9.9
CVE-2026-50747

A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi …

Fix: 5.2.2+
Fix from $2,300 2026-07-02
Unifi Connect Application CRITICAL 10.0
CVE-2026-50746

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a C…

Fix: 3.24.20+
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-4767

Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-A…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-5524

The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin…

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.3
CVE-2026-57683

Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.3
CVE-2026-57679

Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions.

No fix yet
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.8
CVE-2026-57677

Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.6
CVE-2026-57625

Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 10.0
CVE-2026-57624

Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions.

Mitigation only
Fix from $2,300 2026-07-02
Unclassified CRITICAL 9.0
CVE-2026-57623

Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions.

Mitigation only
Fix from $2,300 2026-07-02