Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-71320 picklescan before 0.0.33 contains an incomplete deny-list that fails to block pydoc.locate and operator.methodcaller functions, allowing attackers to… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.6 CVE-2026-55743 The shell tool command allowlist in the SecurityPolicy of OpenHuman desktop agent through 0.54.0 (default Supervised security policy) can be bypassed… Patch available Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54812 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in StylemixThemes Motors allows Blind SQL Injectio… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-47103 Python StateMachine versions 3.0.0 before 3.2.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary code by sup… Python Statemachine 3.2.0+ Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54819 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Webilia Inc. Listdom allows Blind SQL Injection… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54815 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cargo RD Cargo Shipping Location for WooCommerc… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54809 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VillaTheme GIFT4U allows Blind SQL Injection. … Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54808 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Travel WP Travel Gutenberg Blocks allows Bli… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-49268 A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username … Shiro 2.2.1+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-49108 Unauthenticated PHP Object Injection in Moderno < 1.43 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-69127 Unauthenticated PHP Object Injection in Plumbing <= 1.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-69111 Unauthenticated PHP Object Injection in Reisen <= 1.4.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-60236 Deserialization of Untrusted Data vulnerability in EMV Creatify allows Object Injection. This issue affects Creatify: from n/a through 1.5. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-60231 Deserialization of Untrusted Data vulnerability in EMV The Hospital nrghospital allows Object Injection. This issue affects The Hospital: from n/a t… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-60230 Deserialization of Untrusted Data vulnerability in Themeton The Barber Shop allows Object Injection. This issue affects The Barber Shop: from n/a th… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2025-60229 Deserialization of Untrusted Data vulnerability in Themeton Lagom allows Object Injection. This issue affects Lagom: from n/a through 2.0. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2025-59554 Unauthenticated SQL Injection in Advanced Ads – Tracking < 3.0.7 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54811 Unauthenticated SQL Injection in WP eMember < v10.9.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-54807 Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-54806 Unauthenticated PHP Object Injection in WP Activity Log <= 5.6.3.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-54803 Subscriber Privilege Escalation in SMS Alert Order Notifications <= 3.9.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-54194 Contributor PHP Object Injection in Fusion Builder <= 3.15.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54187 Unauthenticated SQL Injection in JetEngine <= 3.8.10.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-54186 Unauthenticated SQL Injection in JobSearch <= 3.2.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-52706 Unauthenticated PHP Object Injection in JetEngine <= 3.8.10 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.0 CVE-2026-52705 Unauthenticated Arbitrary File Upload in SigmaForms Pro – AI Generated Forms <= 1.4.5 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-50203 A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP serv… Apache Airflow Providers Sftp 5.8.1+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-49767 Unauthenticated Broken Authentication in wpForo Forum <= 3.1.0 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-49107 Unauthenticated PHP Object Injection in Thrive Apprentice < 10.8.10.2 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-49084 Unauthenticated SQL Injection in JetEngine < 3.8.9.1 versions. Mitigation only Fix from $2,3002026-06-17