Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-25345 Improper Validation of Specified Quantity in Input vulnerability in GalleryCreator SimpLy Gallery simply-gallery-block allows Accessing Functionality… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-25340 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in NooTheme Jobmonster noo-jobmonster allows Blind… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25035 Authentication Bypass Using an Alternate Path or Channel vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery contest-gallery… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25032 Deserialization of Untrusted Data vulnerability in park_of_ideas Ricky ricky allows Object Injection.This issue affects Ricky: from n/a through < 2.3… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25031 Deserialization of Untrusted Data vulnerability in park_of_ideas Tasty Daily tastydaily allows Object Injection.This issue affects Tasty Daily: from … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25030 Deserialization of Untrusted Data vulnerability in park_of_ideas Goldish goldish allows Object Injection.This issue affects Goldish: from n/a through… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-25029 Deserialization of Untrusted Data vulnerability in park_of_ideas KIDZ kidz allows Object Injection.This issue affects KIDZ: from n/a through <= 5.24. Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-24993 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WPFactory Advanced WooCommerce Product Sales Re… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24989 Deserialization of Untrusted Data vulnerability in FantasticPlugins SUMO Affiliates Pro affs allows Object Injection.This issue affects SUMO Affiliat… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24971 Incorrect Privilege Assignment vulnerability in Elated-Themes Search & Go searchgo allows Privilege Escalation.This issue affects Search & Go: from n… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24968 Incorrect Privilege Assignment vulnerability in Xagio SEO Xagio SEO xagio-seo allows Privilege Escalation.This issue affects Xagio SEO: from n/a thro… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24378 Deserialization of Untrusted Data vulnerability in Metagauss EventPrime eventprime-event-calendar-management allows Object Injection.This issue affec… Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-22507 Deserialization of Untrusted Data vulnerability in AncoraThemes Beelove beelove allows Object Injection.This issue affects Beelove: from n/a through … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-22500 Deserialization of Untrusted Data vulnerability in axiomthemes m2 | Construction and Tools Store m2-ce allows Object Injection.This issue affects m2 … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-22484 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in pebas Lisfinity Core lisfinity-core allows SQL … Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-26833 thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is c… Thumbler after 1.1.2 Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-26832 node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in sr… Tesseract Ocr after 2.2.1 Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-26831 textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious… Textract after 2.5.0 Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-26830 pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructCon… Pdf Image after 2.0.0 Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2025-59707 In N2W before 4.3.2 and 4.4.x before 4.4.1, there is potential remote code execution and account credentials theft because of a spoofing vulnerabilit… N2w 4.3.2+ Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2025-59706 In N2W before 4.3.2 and 4.4.0 before 4.4.1, improper validation of API request parameters enables remote code execution. N2w 4.3.2+ Fix from $2,3002026-03-25 CRITICAL 9.0 CVE-2025-32991 In N2WS Backup & Recovery before 4.4.0, a two-step attack against the RESTful API results in remote code execution. Backup\& Recovery 4.3.2+ Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-4784 A vulnerability was found in code-projects Simple Laundry System 1.0. This affects an unknown function of the file /checkcheckout.php of the componen… Simple Laundry System Mitigation only Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-28858 A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 26.4 and iPadOS 26.4. A remote user may be able to cause un… Ipados 26.4+ Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-28827 A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in macOS Sequoia 15.7.5, macOS So… macOS 14.8.5 / 15.7.5+ Fix from $2,3002026-03-25 CRITICAL 9.3 CVE-2026-20688 A path handling issue was addressed with improved validation. This issue is fixed in iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.… Ipados 14.8.5 / 15.7.5+ Fix from $2,3002026-03-25 CRITICAL 9.8 CVE-2026-24159 NVIDIA NeMo Framework contains a vulnerability where an attacker may cause remote code execution. A successful exploit of this vulnerability might le… Nemo 2.6.2+ Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-24157 NVIDIA NeMo Framework contains a vulnerability in checkpoint loading where an attacker could cause remote code execution. A successful exploit of thi… Nemo 2.6.2+ Fix from $2,3002026-03-24 CRITICAL 9.0 CVE-2025-33244 NVIDIA APEX for Linux contains a vulnerability where an unauthorized attacker could cause a deserialization of untrusted data. This vulnerability aff… Mitigation only Fix from $2,3002026-03-24 CRITICAL 9.8 CVE-2026-33511 pyLoad is a free and open-source download manager written in Python. From version 0.4.20 to before version 0.5.0b3.dev97, the local_check decorator i… Pyload Ng 0.5.0b3.dev97+ Fix from $2,3002026-03-24