Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-34115

Guardian language-system passes the id GET parameter directly into a PHP exec() call in transcribe_amazon.php (line 15) without sanitization: exec(\"…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34114

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate_text.php (line 18) without sanitization: exec(\"php…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34113

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech_text.php (line 18) without sanitization: exec(\"php jo…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34112

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac.php (line 18) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34111

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speechmac_text.php (line 18) without sanitization: exec(\"php…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34110

Guardian language-system passes the id GET parameter directly into a PHP exec() call in complex_start.php (line 14) without sanitization: exec(\"php …

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34109

Guardian language-system passes the id GET parameter directly into a PHP exec() call in speech.php (line 18) without sanitization: exec(\"php jobs/sp…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34108

Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34107

Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34106

Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-34099

Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = …

Mitigation only
Fix from $2,300 2026-07-01
Pacsgear CRITICAL 9.8
CVE-2026-58127

PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj a…

Fix: after 5.2.1
Fix from $2,300 2026-07-01
Pacsgear CRITICAL 9.8
CVE-2026-58126

PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary fil…

Fix: after 5.2.1
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-57517

Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQ…

Mitigation only
Fix from $2,300 2026-07-01
Mediawiki CRITICAL 9.8
CVE-2026-58025

Deserialization of untrusted data vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Imp…

Fix: 1.43.9 / 1.44.6+
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-24270

NVIDIA AIStore framework contains a vulnerability where an attacker could bypass authentication. A successful exploit of this vulnerability might lea…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.0
CVE-2025-23351

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.0
CVE-2025-23350

NVIDIA ConnectX and BlueField contain a vulnerability in the command interface where a local user with virtual function (VF) access may cause a write…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2025-15646

HTML::Gumbo versions before 0.19 for Perl disclose heap memory via type confusion. Support for the <template> element was added to libgumbo 0.10.0 i…

Patch available
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.1
CVE-2026-23537

A vulnerability has been identified in the Feast Feature Server’s `/save-document` endpoint that allows an unauthenticated remote attacker to write a…

Patch available
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-57692

Incorrect Privilege Assignment vulnerability in LCweb PrivateContent allows Privilege Escalation. This issue affects PrivateContent: from n/a throug…

Mitigation only
Fix from $2,300 2026-07-01
Linux Kernel CRITICAL 9.8
CVE-2026-53355

In the Linux kernel, the following vulnerability has been resolved: net: rds: clear i_sends on setup unwind The RDS IB connection teardown path is …

Fix: 3.19 / 4.2+
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.0
CVE-2026-13603

The payment integration pretix-oppwa provides support for the payment providers VR Payment, Hobex, and potentially others based on Oppwa's technolo…

Mitigation only
Fix from $2,300 2026-07-01
Fastify\/middie CRITICAL 9.1
CVE-2026-14198

@fastify/middie versions 9.1.0 through 9.3.2 decode the encoded slash %2F inside path parameter values before matching middleware paths, while Fastif…

Fix: 9.3.3+
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-11387

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnerable to privilege escalation v…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.0
CVE-2026-10539

A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow…

Mitigation only
Fix from $2,300 2026-07-01
Ultravnc CRITICAL 9.1
CVE-2026-7839

UltraVNC repeater through 1.8.2.2 initializes the HTTP administration server with a hardcoded default password. In repeater/webgui/settings.c:197, wh…

Fix: after 1.8.2.2
Fix from $2,300 2026-07-01
Ultravnc CRITICAL 9.8
CVE-2026-7840

UltraVNC repeater through 1.8.2.2 contains a global buffer overflow in its embedded HTTP administration server. The functions wi_senderr() and wi_rep…

Fix: after 1.8.2.2
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.1
CVE-2026-6070

The WP-BusinessDirectory plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Deletion in versions up to and including 4.0.1. This is…

Mitigation only
Fix from $2,300 2026-07-01
Unclassified CRITICAL 9.8
CVE-2026-56700

Grav CMS before 2.0.0-beta.2 contains multiple code-execution vulnerabilities. Three unsafe unserialize() calls - in Scheduler\JobQueue, Framework\Ca…

Mitigation only
Fix from $2,300 2026-06-30