Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-65455 Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-64815 In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files Intellij Idea 2026.2+ Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-64813 In JetBrains IntelliJ IDEA before 2026.2 unauthorized settings modification was possible in a Remote Development session Intellij Idea 2026.2+ Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-64812 In JetBrains IntelliJ IDEA before 2026.2 unauthorized input injection was possible in a Remote Development session Intellij Idea 2026.2+ Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-61951 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-61950 Unauthenticated SQL Injection in TrueBooker <= 1.2.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-61949 Unauthenticated SQL Injection in Bookly <= 27.7 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-61948 Unauthenticated SQL Injection in WPDM – Premium Packages <= 6.2.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 10.0 CVE-2026-59555 Unauthenticated Arbitrary File Deletion in Participants Database <= 2.7.8.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-59544 Unauthenticated PHP Object Injection in Thrive Quiz Builder <= 10.9.3.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.9 CVE-2026-59543 Subscriber Remote Code Execution (RCE) in Advanced Views <= 3.8.11 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-59540 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-59526 Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-59525 Unauthenticated SQL Injection in Participants Database <= 2.7.8.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.3 CVE-2026-59514 Unauthenticated SQL Injection in Buddyboss Platform <= 3.0.5 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.6 CVE-2026-57784 Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.1 CVE-2026-27064 Editor Arbitrary File Upload in Mailster <= 4.1.17 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-65431 Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation… Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-64874 Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-64873 Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15015 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T… Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15011 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, an… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-14282 The GoDAM – Organize WordPress Media Library & File Manager with Unlimited Folders for Images, Videos & more plugin for WordPress is vulnerable to ar… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.0 CVE-2026-16723 A remote code execution (RCE) vulnerability exists in fastjson 1.2.68 through 1.2.83. This vulnerability is exploitable under fastjson's stock defaul… No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-60372 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.9 CVE-2026-60369 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-60367 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 10.0 CVE-2026-60366 Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars). Supported versi… Platform Security For Java No fix yet Fix from $2,3002026-07-22 CRITICAL 9.1 CVE-2026-64798 Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-crypto… No fix yet Fix from $2,3002026-07-22 CRITICAL 9.8 CVE-2026-64796 Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last m… No fix yet Fix from $2,3002026-07-22