Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-9725 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl… Mitigation only Fix from $2,3002026-07-03 CRITICAL 10.0 CVE-2026-13768 Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic… Mitigation only Fix from $2,3002026-07-03 CRITICAL 9.3 CVE-2026-41106 Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network. 365 Copilot Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-26145 Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network. Azure Synapse No fix yet Fix from $2,3002026-07-02 CRITICAL 9.4 CVE-2026-52830 fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se… No fix yet Fix from $2,3002026-07-02 CRITICAL 9.1 CVE-2026-38971 ardupilot through Plane-4.6.3 was found to contain an out-of-bounds read issue in libraries/GCS_MAVLink/GCS_serial_control.cpp in GCS_MAVLINK::handle… Arduplane after 4.6.3 Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-38968 ntopng through 6.6 is vulnerable to Predictable Session Identifier which can lead to Session Hijacking. HTTP session identifiers in src/HTTPserver.cp… Ntopng after 6.6 Fix from $2,3002026-07-02 CRITICAL 9.1 CVE-2026-59099 Apereo CAS 7.3.0 before 8.0.0-RC6 contains a cryptographic vulnerability that allows remote unauthenticated attackers to recover plaintext conversati… Patch available Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-59092 JuiceFS through 1.3.1, fixed in commit a46979c, contains an authentication bypass vulnerability that allows unauthenticated remote attackers to acces… Juicefs after 1.3.1 Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-58466 AutoBangumi before 3.2.8 contains a hard-coded default credentials vulnerability that allows unauthenticated attackers to authenticate as the adminis… Patch available Fix from $2,3002026-07-02 CRITICAL 9.9 CVE-2026-44935 Missing validation of "valuesFrom" references in Helm Deployer of SUSE Rancher Fleet 0.15 before 0.15.2, 0.14 before 0.14.6, 0.13 before 0.13.11 and … Rancher Fleet 0.12.15 / 0.13.11+ Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2024-14037 Redsea Cloud eHR contains an arbitrary file upload vulnerability that allows unauthenticated attackers to achieve remote code execution by uploading … Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2022-50973 Yonyou KSOA 9.0 contains an unauthenticated arbitrary file upload vulnerability in the com.sksoft.bill.ImageUpload servlet that allows unauthenticate… Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-58455EPSS 8% Dockwatch through 0.6.567 contains an unauthenticated OS command injection vulnerability that allows remote attackers to execute arbitrary shell comm… Patch available Fix from $2,3002026-07-02 CRITICAL 10.0 CVE-2026-56004 A shellcode injection in the mercurial handler of the obs tar_scm source service before version 0.12.4 could be used by attackers able to provide a _… Patch available Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-55116 A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in… Unifi Connect 3.4.20+ Fix from $2,3002026-07-02 CRITICAL 9.9 CVE-2026-55115 A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to es… Unifi Protect 7.1.83+ Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-54408 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass auth… Unifi Protect 7.1.83+ Fix from $2,3002026-07-02 CRITICAL 9.1 CVE-2026-54400 A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Applica… Unifi Access 4.2.29+ Fix from $2,3002026-07-02 CRITICAL 9.9 CVE-2026-50748 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Applic… Unifi Access 4.2.29+ Fix from $2,3002026-07-02 CRITICAL 9.9 CVE-2026-50747 A malicious actor with access to the network and low privileges could exploit a series of authenticated SQL Injection vulnerabilities found in UniFi … Unifi Talk Application 5.2.2+ Fix from $2,3002026-07-02 CRITICAL 10.0 CVE-2026-50746 A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Connect Application to execute a C… Unifi Connect Application 3.24.20+ Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-4767 Missing authentication for critical function vulnerability in TR7 Cyber ​​Defense Inc. WAF-ASP allows Authentication Abuse. This issue affects WAF-A… Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-5524 The Divi Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload leading to Remote Code Execution in all versions up to and includin… Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.3 CVE-2026-57683 Unauthenticated SQL Injection in WP Fast Total Search <= 1.80.280 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.3 CVE-2026-57679 Unauthenticated SQL Injection in GeekyBot <= 1.2.5 versions. No fix yet Fix from $2,3002026-07-02 CRITICAL 9.8 CVE-2026-57677 Unauthenticated PHP Object Injection in Novalnet Payment Gateway for WooCommerce <= 12.10.3 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.6 CVE-2026-57625 Unauthenticated Cross Site Scripting (XSS) in Admin and Site Enhancements (ASE) Pro <= 8.8.5 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 10.0 CVE-2026-57624 Unauthenticated Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.46 versions. Mitigation only Fix from $2,3002026-07-02 CRITICAL 9.0 CVE-2026-57623 Unauthenticated Arbitrary Code Execution in W3 Total Cache <= 2.9.4 versions. Mitigation only Fix from $2,3002026-07-02