Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-52785

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. …

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-52782

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/projec…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.6
CVE-2026-52780

OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-46386

OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.6
CVE-2026-33646

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template eng…

Mitigation only
Fix from $2,300 2026-06-26
Dokku CRITICAL 9.9
CVE-2026-54636

Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku us…

Fix: 0.38.7+
Fix from $2,300 2026-06-26
Dokku CRITICAL 9.0
CVE-2026-45408

Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authentic…

Fix: 0.38.2+
Fix from $2,300 2026-06-26
Lxd CRITICAL 9.6
CVE-2026-12411

Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu…

Fix: 6.9+
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-0685

Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.6
CVE-2025-11919

The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/U…

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.1
CVE-2026-57658

Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56070

Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56068

Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56067

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56062

Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-56059

Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-56058

Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-56057

Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56036

Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-56034

Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-56033

Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-56032

Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-56030

Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.8
CVE-2026-56028

Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.9
CVE-2026-56027

Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-54831

Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-54827

Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-54825

Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.

Mitigation only
Fix from $2,300 2026-06-26
Unclassified CRITICAL 9.3
CVE-2026-54820

Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.

Mitigation only
Fix from $2,300 2026-06-26
Youtrack CRITICAL 9.8
CVE-2026-57926

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

Fix: 2026.2.16593+
Fix from $2,300 2026-06-26