Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-71248 Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f… Patch available Fix from $2,3002026-08-05 MEDIUM 6.5 CVE-2026-71247 Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role to fetch and complete fields b… No fix yet Fix from $1,6002026-08-05 HIGH 7.1 CVE-2026-71245 Mautic's getLeadIdsByFieldValueAction (LeadBundle/Controller/AjaxController.php) reads a field parameter from the request, sanitizes it only with Inp… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-71244 Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, reuses the stored password, ac… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-71243 The backmeup npm package assembles shell command strings by directly concatenating its option values (name, source, destination, filter) - e.g. cmd =… No fix yet Fix from $1,9502026-08-05 HIGH 8.3 CVE-2026-71242 Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePol… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-71241 Book-Management-System's Flask API endpoints /student, /record, /books, /find_stu_book, and /find_not_return_book are missing the @login_required dec… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-71239 DjangoCRM's massmail module renders user-controlled EmlMessage fields (subject, content) through Django's Template constructor with no sanitization, … No fix yet Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-71238 DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-71237 Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i… No fix yet Fix from $2,3002026-08-05 HIGH 8.7 CVE-2026-71236 Grocy's API request-body parser (controllers/Api/BaseApiController.php, GetParsedAndFilteredRequestBody) purifies incoming field values with HTMLPuri… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-71235 Magistrala's Rules Engine allows authenticated users to create rules with embedded Go or Lua scripts executed server-side when IoT messages arrive. T… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-71234 Documize Community's attachment download route (domain/attachment/endpoint.go, Download function, registered via AddPublic with no auth middleware) a… No fix yet Fix from $1,9502026-08-05 HIGH 8.7 CVE-2026-71233 InvoiceNinja v5-stable renders an invoice or quote's "terms" field in the client portal using Laravel Blade's raw output directive {!! ->terms !!} (r… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-71232 MacCMS10's admin template editor (application/admin/controller/Template.php) blocks dangerous PHP functions in template content via a blacklist regex… Patch available Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-71231 IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.8 CVE-2026-66747 Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o… No fix yet Fix from $2,3002026-08-05 HIGH 8.8 CVE-2026-60009 In Eclipse Theia versions up to and including 1.73.1, the `@theia/filesystem` backend binds `POST /file-upload` in every filesystem-enabled deploymen… Theia 1.74.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-14574 In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` recursively merges preference va… Theia 1.74.0+ Fix from $1,6002026-08-05 MEDIUM 5.5 CVE-2026-14304 In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChe… Accessibility Tools Framework 3.2.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-12609 In Eclipse Theia versions 1.66.0 and up until including 1.73.1, the `@theia/plugin-ext` backend exposes the `/hostedPlugin/:pluginId/:path(*)` HTTP e… Theia 1.74.0+ Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-44945 A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w… Patch available Fix from $2,3002026-08-05 HIGH 7.3 CVE-2026-25703 NeuVector through 5.4.9 is can potentially leak information from manager /network/graph API due to missing authentication and cached data containing … No fix yet Fix from $1,9502026-08-05 MEDIUM 6.9 CVE-2026-0931 Denial-of-service vulnerability in M-Files Server versions before 26.5.16015.3 allows an authenticated admin user to cause the M-Files Server process… No fix yet Fix from $1,6002026-08-05 CRITICAL 9.0 CVE-2026-10090 A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet… No fix yet Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-10059 A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp… No fix yet Fix from $2,3002026-08-05 MEDIUM 6.5 CVE-2026-7726 The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on the `Layouts_WPB_Remote::tem… No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-7693 The Backup Migration plugin for WordPress is vulnerable to OS Command Injection in all versions up to, and including, 2.1.5.1 due to insufficient san… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-7520 The MailChimp Forms by MailMunch plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `si… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-7444 The Search Analytics for WP plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.16. This is du… No fix yet Fix from $1,9502026-08-05