Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-52785 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. … Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-52782 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects/<A>/settings/projec… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-52780 OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-46386 OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-33646 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template eng… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-54636 Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku us… Dokku 0.38.7+ Fix from $2,3002026-06-26 CRITICAL 9.0 CVE-2026-45408 Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authentic… Dokku 0.38.2+ Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2026-12411 Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another gu… Lxd 6.9+ Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-0685 Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.6 CVE-2025-11919 The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/U… Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.1 CVE-2026-57658 Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56070 Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56068 Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56067 Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56062 Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-56059 Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-56058 Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-56057 Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56036 Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-56034 Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-56033 Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-56032 Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-56030 Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-56028 Unauthenticated Privilege Escalation in Easy Elements for Elementor &#8211; Addons &amp; Website Templates <= 1.4.9 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.9 CVE-2026-56027 Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54831 Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54827 Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54825 Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.3 CVE-2026-54820 Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. Mitigation only Fix from $2,3002026-06-26 CRITICAL 9.8 CVE-2026-57926 In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack Youtrack 2026.2.16593+ Fix from $2,3002026-06-26