Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-50627 The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-49875 Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configuration… Cxf 4.1.7 / 4.2.2+ Fix from $2,3002026-06-12 CRITICAL 9.4 CVE-2026-11535 An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’… No fix yet Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-48611 Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthoriz… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.9 CVE-2026-47370 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.9 CVE-2026-47369 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices run… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.9 CVE-2026-47367 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agen… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.9 CVE-2026-47365 Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant… Mitigation only Fix from $2,3002026-06-12 CRITICAL 9.8 CVE-2026-45060 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-42846 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-49060 Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App … Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.3 CVE-2026-42647 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. … Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.3 CVE-2026-39494 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind … Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.6 CVE-2026-12027 Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process … Chrome 149.0.7827.115+ Fix from $2,3002026-06-11 CRITICAL 9.0 CVE-2026-41005 Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity P… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.4 CVE-2026-49973 Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial… Patch available Fix from $2,3002026-06-11 CRITICAL 9.5 CVE-2026-47174 In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.5 CVE-2026-47172 Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository has a privileged de… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.1 CVE-2026-45177 Idira Secrets Manager SaaS Edge versions prior to 1.8 exhibit improper access control within its internal authentication components. A remote, unauth… Idira Secrets Manager Edge 1.8+ Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-49261 MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8… MariaDB 10.6.27 / 10.11.18+ Fix from $2,3002026-06-11 CRITICAL 9.1 CVE-2026-9648 The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alterna… Patch available Fix from $2,3002026-06-11 CRITICAL 9.9 CVE-2026-11839 Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web S… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-38581 SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFor… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-7852 Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects Lim… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-11561 Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Inform… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.4 CVE-2026-4764 A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user wit… Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-41699 Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious… Spring For Graphql 1.3.9 / 1.4.5.1+ Fix from $2,3002026-06-11 CRITICAL 9.8 CVE-2026-35273 KEVEPSS 95% Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions t… Peoplesoft Enterprise Peopletools Mitigation only Fix from $2,3002026-06-11 CRITICAL 9.6 CVE-2026-46703 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted … Mitigation only Fix from $2,3002026-06-10 CRITICAL 10.0 CVE-2026-46695 Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted … Patch available Fix from $2,3002026-06-10