Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-6382 The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.… Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-14808 Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to … Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.8 CVE-2026-14807 ERP App developed by PROG MIS has a Use of Hard-coded Credentials vulnerability, allowing unauthenticated remote attackers to log in to view applicat… Mitigation only Fix from $2,3002026-07-06 CRITICAL 9.2 CVE-2026-59509 An unauthenticated improper input validation vulnerability in the POST /fetch_cve_data endpoint in cve-search. A remote attacker can manipulate reque… Patch available Fix from $2,3002026-07-05 CRITICAL 9.8 CVE-2026-14535 In Trail of Bits fickling versions up to and including 0.1.11, the UnsafeImportsML analysis pass unconditionally calls AnalysisContext.shorten_code(n… Fickling after 0.1.11 Fix from $2,3002026-07-04 CRITICAL 9.6 CVE-2026-58426 Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write Patch available Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-58422 Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts Patch available Fix from $2,3002026-07-03 CRITICAL 10.0 CVE-2026-57983 Improper authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network. Edge Chromium 150.0.4078.48+ Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-27780 Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass b… Patch available Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-26292 Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration tran… Patch available Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-26247 Gitea versions before 1.25.5 do not persist the OAuth2 PKCE S256 challenge method correctly during authorization, allowing token exchange without the… Patch available Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-26232 Gitea versions before 1.25.5 do not consistently enforce OAuth2 authorization code expiry and single-use behavior during token exchange. Patch available Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-25718 Gitea versions before 1.25.5 mishandle path resolution during template repository generation, allowing template processing to read or write through s… Patch available Fix from $2,3002026-07-03 CRITICAL 9.6 CVE-2026-22874 Gitea versions up to and including 1.26.2 have incomplete SSRF protection in webhook and migration allow-list filtering. Patch available Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-20706 Gitea versions up to and including 1.26.1 allow repository archive downloads to bypass token scope checks on the web archive download endpoint. Patch available Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-22547 Gitea versions before 1.25.5 lack validation constraints for repository creation fields, including length-limited template fields and trust model or … Patch available Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-20896 Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user w… Patch available Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-12481 A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la… Keras Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-56015 Net::IP::LPM versions through 1.10 for Perl allow a heap out-of-bounds read via an unbounded prefix length. add() passes the prefix string to the tr… Patch available Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-4321 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertisi… Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-47898 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap… Lucene.net Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-14544 A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attac… Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-9079 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get … Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-8927 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentic… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-8926 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-8925 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-8924 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-11856 Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a diff… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.1 CVE-2026-11564 libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle th… Curl 8.21.0+ Fix from $2,3002026-07-03 CRITICAL 9.8 CVE-2026-10536 A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CUR… Curl 8.21.0+ Fix from $2,3002026-07-03