Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-78211 4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malic… No fix yet Fix from $5,7502026-08-24 CRITICAL 9.9 CVE-2026-78169 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempS… No fix yet Fix from $5,7502026-08-24 CRITICAL 9.8 CVE-2026-78168 A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component … No fix yet Fix from $5,7502026-08-24 CRITICAL 10.0 CVE-2026-78167 A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session… No fix yet Fix from $5,7502026-08-24 CRITICAL 9.4 CVE-2026-78207 exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or pr… No fix yet Fix from $5,7502026-08-24 CRITICAL 9.8 CVE-2026-8445 justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a… No fix yet Fix from $5,7502026-08-23 CRITICAL 9.8 CVE-2026-7808 justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive s… No fix yet Fix from $5,7502026-08-23 CRITICAL 9.8 CVE-2026-5388 justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Ma… No fix yet Fix from $5,7502026-08-23 CRITICAL 9.9 CVE-2026-78155 privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges No fix yet Fix from $5,7502026-08-23 CRITICAL 9.9 CVE-2026-78050 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&sec… No fix yet Fix from $5,7502026-08-23 CRITICAL 9.8 CVE-2026-4703 The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … No fix yet Fix from $5,7502026-08-22 CRITICAL 9.5 CVE-2026-77992 Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform an… No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76607 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76606 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2. No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76604 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable t… No fix yet Fix from $5,7502026-08-22 CRITICAL 9.3 CVE-2026-76602 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries… No fix yet Fix from $5,7502026-08-22 CRITICAL 9.3 CVE-2026-76571 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed… No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-77946 A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/app… No fix yet Fix from $5,7502026-08-22 CRITICAL 9.8 CVE-2026-78003 The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including… No fix yet Fix from $5,7502026-08-22 CRITICAL 9.3 CVE-2026-12710 A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows … No fix yet Fix from $5,7502026-08-22 CRITICAL 9.8 CVE-2026-77002 The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, … No fix yet Fix from $5,7502026-08-22 CRITICAL 9.8 CVE-2026-77001 The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or no… No fix yet Fix from $5,7502026-08-22 CRITICAL 9.8 CVE-2026-77000 The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before… No fix yet Fix from $5,7502026-08-22 CRITICAL 9.1 CVE-2026-49849 xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administr… Patch available Fix from $5,7502026-08-21 CRITICAL 9.3 CVE-2026-77415 JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weakn… Patch available Fix from $5,7502026-08-21 CRITICAL 9.3 CVE-2026-77414 JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOw… Patch available Fix from $5,7502026-08-21 CRITICAL 9.3 CVE-2026-77413 JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwn… Patch available Fix from $5,7502026-08-21 CRITICAL 9.8 CVE-2026-76904 GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,… Patch available Fix from $5,7502026-08-21 CRITICAL 9.9 CVE-2026-62283 Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 thro… Patch available Fix from $5,7502026-08-21