Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-14162

Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-13766

DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass…

Patch available
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-9711

The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12076

Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to e…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12819

Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated…

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.3
CVE-2026-12818

Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP …

Mitigation only
Fix from $2,300 2026-06-30
Unclassified CRITICAL 9.8
CVE-2026-12073

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio…

Mitigation only
Fix from $2,300 2026-06-30
Tomcat CRITICAL 9.1
CVE-2026-55276

Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not inc…

Fix: 9.0.119 / 10.1.56+
Fix from $2,300 2026-06-29
Tomcat CRITICAL 9.1
CVE-2026-53434

Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apach…

Fix: 9.0.119 / 10.1.56+
Fix from $2,300 2026-06-29
Unclassified CRITICAL 9.6
CVE-2026-57498

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller…

Mitigation only
Fix from $2,300 2026-06-29
Ipados CRITICAL 9.1
CVE-2026-39868

This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS S…

Fix: 26.5.2+
Fix from $2,300 2026-06-29
Unclassified CRITICAL 9.1
CVE-2026-37637

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component

No fix yet
Fix from $2,300 2026-06-29
Application Load Balancer CRITICAL 9.8
CVE-2026-13763

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana…

Mitigation only
Fix from $2,300 2026-06-29
Cloudfront CRITICAL 9.8
CVE-2026-13762

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod…

Mitigation only
Fix from $2,300 2026-06-29
Unclassified CRITICAL 9.8
CVE-2026-56782

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers…

Patch available
Fix from $2,300 2026-06-29
Mcp Toolbox For Databases CRITICAL 9.1
CVE-2026-11720

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL bui…

Fix: 1.3.0+
Fix from $2,300 2026-06-29
Snowflake Cli CRITICAL 9.6
CVE-2026-13751

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reade…

Fix: 3.19.0+
Fix from $2,300 2026-06-29
Unclassified CRITICAL 9.9
CVE-2026-57331

Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions.

Mitigation only
Fix from $2,300 2026-06-29
Page Builder Ck CRITICAL 9.8
CVE-2026-56290 KEVEPSS 30%

Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl…

Fix: 3.6.0+
Fix from $2,300 2026-06-29
Joomcck CRITICAL 9.8
CVE-2026-49048

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request pa…

Fix: after 6.4.0
Fix from $2,300 2026-06-28
Unclassified CRITICAL 9.9
CVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig …

Mitigation only
Fix from $2,300 2026-06-28
Unclassified CRITICAL 9.8
CVE-2026-12415

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account…

Mitigation only
Fix from $2,300 2026-06-27
Dmp 5000 Firmware CRITICAL 9.8
CVE-2026-31928

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed du…

Fix: 8.117.0.0 / 9.43.0.0+
Fix from $2,300 2026-06-26
Kestra CRITICAL 10.0
CVE-2026-53576

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Kestra CRITICAL 10.0
CVE-2026-49869

Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().…

Fix: 1.0.45 / 1.3.21+
Fix from $2,300 2026-06-26
Budibase CRITICAL 9.6
CVE-2026-54352

Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a b…

Fix: 3.39.9+
Fix from $2,300 2026-06-26
Budibase CRITICAL 9.6
CVE-2026-54351

Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HT…

Fix: 3.39.9+
Fix from $2,300 2026-06-26
Budibase CRITICAL 9.8
CVE-2026-54350

Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the…

Fix: 3.39.12+
Fix from $2,300 2026-06-26
Budibase CRITICAL 9.4
CVE-2026-50137

Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-so…

Fix: 3.39.0+
Fix from $2,300 2026-06-26
Linux Kernel CRITICAL 9.8
CVE-2026-53309

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs…

Fix: 5.10.258 / 5.15.209+
Fix from $2,300 2026-06-26