Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-66803 Improper access control in Azure Cosmos DB allows an unauthorized attacker to execute code over a network. Azure Cosmos Db No fix yet Fix from $2,3002026-07-30 CRITICAL 9.3 CVE-2026-66418 OpenClaw Dashboard v3.0.0 contains a stored cross-site scripting vulnerability that allows unauthenticated remote attackers to inject arbitrary HTML … No fix yet Fix from $2,3002026-07-30 MEDIUM 6.1 CVE-2026-61526 AdonisJS HTTP Server is a package for handling HTTP requests in the AdonisJS framework. In versions 8.0.0-next.0 through 8.2.0 and 9.0.0 through 9.0.… Patch available Fix from $1,6002026-07-30 MEDIUM 5.3 CVE-2026-55777 GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to 1.11, the pa… Patch available Fix from $1,6002026-07-30 HIGH 8.7 CVE-2026-55768 GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. Prior to version 1.11… Patch available Fix from $1,9502026-07-30 HIGH 7.1 CVE-2026-54715 GoAccess is a real-time web log analyzer and interactive viewer that runs in a terminal in *nix systems or through the browser. In version 1.10.2, pa… Patch available Fix from $1,9502026-07-30 CRITICAL 9.1 CVE-2026-52539 Outstatic CMS <= 2.1.9 contains a hardcoded JWT signing secret. When the OST_TOKEN_SECRET environment variable is not set, the application falls back… No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-35847 An issue in dnsmgr v.2.15 and before allows a local attacker to execute arbitrary code via the ping function of the CheckUils.php file Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69931 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_membership.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69947 SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in customeredit.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69941 SourceCodester Tailor Management System 1.0 is vulnerable to SQL Injection in addmeasurement.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69938 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in renew.php via the parameter membershipType. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69937 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in the edit_type.php endpoint via the Parameter id. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69936 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /edit_member.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69935 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69934 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69933 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69930 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. No fix yet Fix from $2,3002026-07-30 MEDIUM 6.1 CVE-2025-65342 code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2025-65341 Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. No fix yet Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2025-65336 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67594 Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes… No fix yet Fix from $2,3002026-07-30 MEDIUM 5.7 CVE-2026-67550 re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a… Patch available Fix from $1,6002026-07-30 MEDIUM 6.4 CVE-2026-67530 WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its… Patch available Fix from $1,6002026-07-30 HIGH 7.6 CVE-2026-67527 OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and al… Patch available Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-67208 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by … No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-67207 Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users… Mitigation only Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-67206 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-66756 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a… Tika No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-66755 Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker… Tika 3.3.2+ Fix from $1,9502026-07-30