Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 8.2
CVE-2017-20262
Joomla! Component Ajax Quiz 1.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by inj…
Ajax Quiz
No fix yet
HIGH 8.8
CVE-2026-38529
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to…
Krayin Crm
No fix yet
HIGH 8.1
CVE-2026-38530
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated atta…
Krayin Crm
No fix yet
HIGH 8.1
CVE-2026-38532
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated att…
Krayin Crm
No fix yet
MEDIUM 5.4
CVE-2021-41074
A CSRF issue in index.php in QloApps hotel eCommerce 1.5.1 allows an attacker to change the admin's email address via a crafted HTML document.
Qloapps
Mitigation only
CRITICAL 9.8
CVE-2025-67325
Unrestricted file upload in the hotel review feature in QloApps versions 1.7.0 and earlier allows remote unauthenticated attackers to achieve remote …
Qloapps
after 1.7.0
CRITICAL 9.8
CVE-2026-21450
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via type parameter, w…
Bagisto
2.3.10+
HIGH 8.8
CVE-2026-21449
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection via first name and la…
Bagisto
2.3.10+
HIGH 8.4
CVE-2026-21451
Bagisto is an open source laravel eCommerce platform. A stored Cross-Site Scripting (XSS) vulnerability exists in Bagisto prior to version 2.3.10 wit…
Bagisto
2.3.10+
CRITICAL 9.8
CVE-2026-21448
Bagisto is an open source laravel eCommerce platform. Versions prior to 2.3.10 are vulnerable to server-side template injection. When a normal custom…
Bagisto
2.3.10+
HIGH 7.1
CVE-2026-21447
Bagisto is an open source laravel eCommerce platform. Prior to version 2.3.10, an Insecure Direct Object Reference vulnerability in the customer orde…
Bagisto
2.3.10+
CRITICAL 9.8
CVE-2026-21446
Bagisto is an open source laravel eCommerce platform. In versions on the 2.3 branch prior to 2.3.10, API routes remain active even after initial inst…
Bagisto
2.3.10+
HIGH 7.8
CVE-2025-62417
Bagisto is an open source laravel eCommerce platform. When product data that begins with a spreadsheet formula character (for example =, +, -, or @) …
Bagisto
No fix yet
MEDIUM 6.8
CVE-2025-62416
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user i…
Bagisto
No fix yet
HIGH 8.3
CVE-2025-60880
An authenticated stored XSS vulnerability exists in the Bagisto 2.3.6 admin panel's product creation path, allowing an attacker to upload a crafted S…
Bagisto
No fix yet
MEDIUM 6.5
CVE-2025-56426
An issue WebKul Bagisto v.2.3.6 allows a remote attacker to execute arbitrary code via the Cart/Checkout API endpoint, specifically, the price calcul…
Bagisto
No fix yet
MEDIUM 5.3
CVE-2025-10759
A vulnerability was detected in Webkul QloApps up to 1.7.0. This affects an unknown function of the component CSRF Token Handler. Performing manipula…
Qloapps
after 1.7.0
HIGH 8.8
CVE-2025-55745
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Versions 0.3.0 and prior are vulnerable to CSV i…
Unopim
0.3.1+
HIGH 8.1
CVE-2025-55741
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. In versions 0.3.0 and earlier, users without the…
Unopim
0.3.1+
HIGH 8.8
CVE-2025-55743
UnoPim is an open-source Product Information Management (PIM) system built on the Laravel framework. Before 0.2.1, the image upload at the user creat…
Unopim
0.2.1+
HIGH 7.2
CVE-2025-6173
A vulnerability classified as critical was found in Webkul QloApps 1.6.1. Affected by this vulnerability is an unknown functionality of the file /adm…
Qloapps
No fix yet
MEDIUM 6.1
CVE-2025-40675
A Reflected Cross-Site Scripting (XSS) vulnerability has been found in Bagisto v2.0.0. This vulnerability allows an attacker to execute JavaScript co…
Bagisto
2.2.3+
MEDIUM 5.4
CVE-2025-3568
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functiona…
Krayin Crm
No fix yet
MEDIUM 6.1
CVE-2025-1155
A vulnerability, which was classified as problematic, was found in Webkul QloApps 1.6.1. This affects an unknown part of the file /stores of the comp…
Qloapps
No fix yet
MEDIUM 5.4
CVE-2024-50637
UnoPim 0.1.3 and below is vulnerable to Cross Site Scripting (XSS) in the Create User function. This allows attackers to perform XSS via an SVG docum…
Unopim
0.1.4+
CRITICAL 9.6
CVE-2024-46367
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submittin…
Krayin Crm
Mitigation only
HIGH 8.8
CVE-2024-46366
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template co…
Krayin Crm
Mitigation only
HIGH 7.2
CVE-2024-40318
An arbitrary file upload vulnerability in Webkul Qloapps v1.6.0.0 allows attackers to execute arbitrary code via uploading a crafted file.
Qloapps
No fix yet
MEDIUM 6.5
CVE-2023-36238
Insecure Direct Object Reference (IDOR) in Bagisto v.1.5.1 allows an attacker to obtain sensitive information via the invoice ID parameter.
Bagisto
No fix yet
MEDIUM 6.5
CVE-2024-27499
Bagisto v1.5.1 is vulnerable for Cross site scripting(XSS) via png file upload vulnerability in product review option.
Bagisto
Patch available