Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-72562 An SQL injection vulnerability in Pimcore admin-ui-classic-bundle through version 2.3 allows authenticated backend users to execute arbitrary SQL via… No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72561 A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfi… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-72560 A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTION_ENABLED is set to false by… No fix yet Fix from $1,6002026-08-11 MEDIUM 5.4 CVE-2026-72559 A stored cross-site scripting vulnerability in HortusFox 5.9 allows authenticated workspace members to inject persistent JavaScript into plant notes … No fix yet Fix from $1,6002026-08-11 HIGH 8.8 CVE-2026-72558 An SQL injection vulnerability in CiviCRM through 6.18.alpha1 allows authenticated staff to read the entire database via the contact search RLIKE cla… No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72557 An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP scripts via … No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72556 A remote code execution vulnerability in ZoneMinder 1.39.17 allows any authenticated user to execute OS commands by exploiting a broken permission ch… No fix yet Fix from $1,9502026-08-11 HIGH 8.1 CVE-2026-72555 A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 exists because the Config.roles_active flag defaults to fal… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-72554 A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer to read ticket conversations … No fix yet Fix from $1,6002026-08-11 MEDIUM 5.4 CVE-2026-72553 A stored cross-site scripting vulnerability in ElkArte Forum 2.0 Beta 1 allows any registered member to inject persistent JavaScript into the profile… No fix yet Fix from $1,6002026-08-11 HIGH 7.5 CVE-2026-72552 A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP requests to… No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72551 A remote code execution vulnerability in Apioo Fusio 8.8.3 allows authenticated users with the Developer role to execute arbitrary OS commands by exp… No fix yet Fix from $1,9502026-08-11 CRITICAL 9.8 CVE-2026-72550 An SQL injection vulnerability in Friendica through the 2026.08-dev branch allows unauthenticated remote attackers to execute arbitrary SQL statement… No fix yet Fix from $2,3002026-08-11 MEDIUM 5.3 CVE-2026-72549 An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or u… No fix yet Fix from $1,6002026-08-11 HIGH 7.5 CVE-2026-72548 An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation … No fix yet Fix from $1,9502026-08-11 HIGH 7.1 CVE-2026-72547 An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to bulk import attende… No fix yet Fix from $1,9502026-08-11 HIGH 7.1 CVE-2026-72546 An insecure direct object reference vulnerability in Attendize through commit 9289acb allows any authenticated event organiser to inject attendees an… No fix yet Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-72545 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any con… No fix yet Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-72544 An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail… No fix yet Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-72543 An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any con… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.4 CVE-2026-72542 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows authenticated operators to write job progress and read job met… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.5 CVE-2026-72541 A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to overwrite any resource t… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.5 CVE-2026-72539 An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless … No fix yet Fix from $1,6002026-08-11 HIGH 8.8 CVE-2026-72538 An argument injection vulnerability in PrefectHQ Prefect through 3.8.2 allows authenticated users to achieve remote code execution via the git_clone … No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72537 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token… No fix yet Fix from $1,9502026-08-11 HIGH 8.6 CVE-2026-72536 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to manipulate any tenant Stripe subs… No fix yet Fix from $1,9502026-08-11 HIGH 8.6 CVE-2026-72535 A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint Stripe Billing Portal sessio… No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72534 A privilege escalation vulnerability in Authentik Security authentik through 2026.5.6 allows an attacker with a source-scoped SCIM provisioning token… No fix yet Fix from $1,9502026-08-11 HIGH 8.8 CVE-2026-72533 An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization … No fix yet Fix from $1,9502026-08-11 HIGH 7.4 CVE-2026-50237 A Server-Side Request Forgery and supply chain flaw was found in the OpenShift Console Helm catalog proxy. A namespace tenant can plant a ProjectHelm… No fix yet Fix from $1,9502026-08-11