Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-47724 nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.4, the `/api/v1/*` route surface trust… Patch available Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15981 The SAML Single Sign On – SSO Login plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.4.4. This is … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.9 CVE-2026-15630 A non-global organization admin in one tenant can bypass tenant boundaries to delete, create, or modify resources in any other tenant by exploiting a… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15967 Insufficient session expiration vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15966 Permissive cross-domain security policy with untrusted domains vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-10697 Improper Authentication vulnerability in Progress MOVEit Transfer. This issue affects MOVEit Transfer: before 2025.1.5, from 2026.0.0 before 2026.0.… Moveit Transfer 2025.1.5 / 2026.0.3+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-63359 The Appriss Insights (Equifax) Victim Information Notification Exchange (VINE) applications allow an unauthenticated attacker to send a specially-cra… Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.4 CVE-2026-47670 DbGate is cross-platform database manager. Versions 7.1.8 and prior are vulnerable to authenticated Remote Code Execution (RCE). Any user with valid … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-47669 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the `unzipDirectory()` function in `packages/api/src/shell/unzipDirectory.js`… No fix yet Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-6516 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-65701 SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows una… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-65700 h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read,… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.9 CVE-2026-47752 Tugtainer is a self-hosted app for automating updates of Docker containers. Versions prior to 1.30.2 are vulnerable to Server-Side Template Injection… No fix yet Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-47668 DbGate is cross-platform database manager. In versions 7.1.8 and prior, DbGate's JSON script runner (`POST /runners/start`) allows remote code execut… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.9 CVE-2026-44210 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. V… Kata Containers 3.31.0+ Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-65761 Joomla Extension - joomshaper.com - Unauthenticated SQL injection in Easy Store extension 1.0.0-2.0.1 - Improper validation of order parameters lead … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.2 CVE-2026-65760 Joomla Extension - joomshaper.com - cross-customer order and personal information disclosure in Easy Store extension 1.0.0-2.0.1 - Improper access ch… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-15617 Logto performs principal lookup without normalizing email and identifier strings, enabling principal collision and unauthorized account access via ca… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-15616 Logto does not enforce locally configured MFA during SSO authentication, allowing users to bypass second-factor requirements and grants unauthorized … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-15612 Logto bypasses OIDC nonce validation when the nonce claim is absent from the id_token, enabling replay of authentication tokens and weakening session… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-15611 Logto allows unverified email-based SSO account linking, enabling an attacker to register an identity at a permissive IdP using a victim’s email and … No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-65689 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that all… Standalone Report Designer 14.1.12+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-65688 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allow… Standalone Report Designer 14.1.12+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-65687 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows… Standalone Report Designer 14.1.12+ Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-65907 In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible No fix yet Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-65906 In JetBrains TeamCity before 2026.1.2, 2025.11.6 сode execution via Kotlin DSL sandbox escape was possible Teamcity 2025.11.6 / 2026.1.2+ Fix from $2,3002026-07-23 CRITICAL 9.6 CVE-2026-65606 SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references … Patch available Fix from $2,3002026-07-23 CRITICAL 9.6 CVE-2026-65605 SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is ren… Patch available Fix from $2,3002026-07-23 CRITICAL 9.6 CVE-2026-65471 Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions. Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-65461 Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions. Mitigation only Fix from $2,3002026-07-23