Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-63233 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall an… Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2026-63232 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcem… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-63230 A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, … No fix yet Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-63229 A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO … Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2026-63227 An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP we… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-13423 The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which … No fix yet Fix from $2,3002026-07-29 CRITICAL 9.8 CVE-2026-18072 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a H… No fix yet Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-64863 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOV… Patch available Fix from $2,3002026-07-28 CRITICAL 9.1 CVE-2026-62325 goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handl… Patch available Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-54658 Hypequery is a TypeScript semantic layer for ClickHouse. Prior to 2.5.1, escapeValue() in packages/clickhouse/src/core/utils.ts did not escape backsl… Patch available Fix from $2,3002026-07-28 CRITICAL 9.4 CVE-2026-6881 A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive … Mitigation only Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14976 IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.8 is affected by remote code execution with the collectiveController-1.0 feature e… Websphere Application Server 26.0.0.9+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14974 IBM WebSphere Application Server 8.5, and 9.0 traditional could allow a remote attacker to execute arbitrary code caused by unsafe deserialization of… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.3 CVE-2026-14973 IBM Aspera Desktop App 1.0.5 through 1.0.19 IBM Aspera for desktop can allow files to be written outside of the user's selected download destination. Aspera after 1.0.19 Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14512 IBM WebSphere Application Server 9.0, and 8.5 traditional is vulnerable to pre-authentication unsafe deserialization which could allow a remote attac… Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-14446 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to broken access control/privilege escalation in the administrative console. Websphere Application Server 8.5.5.30 / 9.0.5.28+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-16184 IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to bypass authentication by sending a crafted unauthenticated request. Websphere Application Server 8.5.5.31 / 9.0.5.29+ Fix from $2,3002026-07-28 CRITICAL 10.0 CVE-2026-16498 The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode … No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51268 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the host parsing logic. The dismantle_host() function parses untr… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.6 CVE-2026-51271 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the WAV header parsing function read_WAV_Header(). The fun… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51267 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the URL path concatenation and encoding module. The application s… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51266 schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vulnerability in the HTTP request header construction logic. The application dynam… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51263 schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. The Audio::openai_speech function in the Audio library manually constructs JSON r… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.2 CVE-2026-67174 Pivotick contains a DOM-based cross-site scripting vulnerability in its generic UI element resolution and icon-rendering utilities. The tryResolveHT… Patch available Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-66713 Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component  in Apache Software Foundation Apache Axis2/Java through 2.0.0… Axis2\/java 2.0.1+ Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51261 Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfaul1 ESP32-audioI2S 3.4.5 creates a race condition between concurrent tasks. The… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.4 CVE-2026-51260 Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of schreibfaul1 ESP32-audioI2S 3.4.5 allows remote heap buffer overflow. The code cop… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51259 Unchecked unsigned integer overflow in buffer size calculation in schreibfaul1 ESP32-audioI2S 3.4.5 leads to undersized PSRAM buffer allocation. Subs… No fix yet Fix from $2,3002026-07-28 CRITICAL 9.8 CVE-2026-51252 schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability in the MP3Decoder::UnpackSFMPEG1 function due to missing input validation on at… No fix yet Fix from $2,3002026-07-28 CRITICAL 10.0 CVE-2026-65880 Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed code exec… No fix yet Fix from $2,3002026-07-28