Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-14162 Hospital Queuing Management developed by Advantech has a Sensitive Data Exposure vulnerability, allowing unauthenticated remote attackers to access a… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-13766 DBIx::QuickORM versions before 0.000026 for Perl allow SQL injection via unquoted SQL identifiers. The default SQL builder, a SQL::Abstract subclass… Patch available Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-9711 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-12076 Raytha CMS is vulnerable to SQL Injection within the OData filter parsing pipeline.  The vulnerability allows a remote, unauthenticated attacker to e… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-12819 Delta Electronics DVP12SE PLC exposes a Modbus TCP service over a specified port without authentication or access control, permitting unauthenticated… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.3 CVE-2026-12818 Delta Electronics DVP12SE PLCs are susceptible to a resource allocation vulnerability without limits or throttling (CWE-770) within their Modbus TCP … Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.8 CVE-2026-12073 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… Mitigation only Fix from $2,3002026-06-30 CRITICAL 9.1 CVE-2026-55276 Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not inc… Tomcat 9.0.119 / 10.1.56+ Fix from $2,3002026-06-29 CRITICAL 9.1 CVE-2026-53434 Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apach… Tomcat 9.0.119 / 10.1.56+ Fix from $2,3002026-06-29 CRITICAL 9.6 CVE-2026-57498 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller… Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.1 CVE-2026-39868 This issue was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.5.2 and iPadOS 26.5.2, macOS S… Ipados 26.5.2+ Fix from $2,3002026-06-29 CRITICAL 9.1 CVE-2026-37637 An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component No fix yet Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-13763 Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana… Application Load Balancer Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-13762 Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod… Cloudfront Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-56782 Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers… Patch available Fix from $2,3002026-06-29 CRITICAL 9.1 CVE-2026-11720 A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL bui… Mcp Toolbox For Databases 1.3.0+ Fix from $2,3002026-06-29 CRITICAL 9.6 CVE-2026-13751 Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reade… Snowflake Cli 3.19.0+ Fix from $2,3002026-06-29 CRITICAL 9.9 CVE-2026-57331 Performer Arbitrary File Deletion in Paid Videochat Turnkey Site <= 7.4.8 versions. Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-56290 KEVEPSS 30% Joomla Extension - joomlack.fr - Unauthenticated file upload in Page Builder CK extension < 3.6.0 - The Joomla extension Page Builder CK is vulnerabl… Page Builder Ck 3.6.0+ Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-49048 The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request pa… Joomcck after 6.4.0 Fix from $2,3002026-06-28 CRITICAL 9.9 CVE-2026-58053 Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig … Mitigation only Fix from $2,3002026-06-28 CRITICAL 9.8 CVE-2026-12415 The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account… Mitigation only Fix from $2,3002026-06-27 CRITICAL 9.8 CVE-2026-31928 The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed du… Dmp 5000 Firmware 8.117.0.0 / 9.43.0.0+ Fix from $2,3002026-06-26 CRITICAL 10.0 CVE-2026-53576 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 CRITICAL 10.0 CVE-2026-49869 Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().… Kestra 1.0.45 / 1.3.21+ Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-54352 Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a b… Budibase 3.39.9+ Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-54351 Budibase is an open-source low-code platform. Prior to 3.39.9, the webhook trigger endpoint in Budibase is publicly accessible and passes the full HT… Budibase 3.39.9+ Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-54350 Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the… Budibase 3.39.12+ Fix from $2,3002026-06-26 CRITICAL 9.4 CVE-2026-50137 Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-so… Budibase 3.39.0+ Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-53309 In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs… Linux Kernel 5.10.258 / 5.15.209+ Fix from $2,3002026-06-26