Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-16051 The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, no… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-15039 The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users t… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.9 CVE-2026-72526 A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.6 CVE-2026-70398 A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated u… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.1 CVE-2026-68431 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applie… No fix yet Fix from $2,3002026-08-12 CRITICAL 9.8 CVE-2026-68067 The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the accoun… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-67568 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which … No fix yet Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-5917 libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-71290 Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe… Httpclient 5.6.4+ Fix from $2,3002026-08-11 CRITICAL 9.4 CVE-2026-66147 An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.9 CVE-2026-48765 TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from… Patch available Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-73034 DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s… Patch available Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-73032 PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou… Patch available Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-66145 An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke… No fix yet Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-45618 LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-16230 The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-73211 PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac… Patch available Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2026-73090 PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd… Patch available Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-71398 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of … No fix yet Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-71362 Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-69102 MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica… Patch available Fix from $2,3002026-08-11 CRITICAL 9.0 CVE-2026-48381 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha… No fix yet Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-47705 TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sani… Patch available Fix from $2,3002026-08-11 CRITICAL 10.0 CVE-2026-27302 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of … No fix yet Fix from $2,3002026-08-11 CRITICAL 9.6 CVE-2026-71384 is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability… Coldfusion No fix yet Fix from $2,3002026-08-11 CRITICAL 9.3 CVE-2026-70306 Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t… Sharepoint Server 16.0.19725.20434+ Fix from $2,3002026-08-11 CRITICAL 9.1 CVE-2026-69223 Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend… Allura 1.19.1+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-65791 Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-65768 Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec… Teams 1.0.0.2026133602+ Fix from $2,3002026-08-11 CRITICAL 9.8 CVE-2026-62893 Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network. Windows 10 1607 10.0.14393.9418 / 10.0.17763.9115+ Fix from $2,3002026-08-11