Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-69935 CodeAstro Membership Management System 1.0 is vulnerale to SQL Injection in the report.php and revenue_report.php via the fromDate parameter. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69934 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /delete_members.php?id=1. No fix yet Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69933 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /memberProfile.php?id=1. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2025-69930 CodeAstro Membership Management System 1.0 is vulnerable to SQL Injection in /print_membership_card.php?id=1. No fix yet Fix from $2,3002026-07-30 MEDIUM 6.1 CVE-2025-65342 code-projects Blood System 1.0 is vulnerable to Cross Site Scripting (XSS) in /don.php via the city field. No fix yet Fix from $1,6002026-07-30 MEDIUM 6.1 CVE-2025-65341 Ecommerce Fruits Bazar 1.0 is vulnerable to Cross Site Scripting (XSS) in admin/edit_product.php. No fix yet Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2025-65336 Ecommerce-project-with-php-and-mysqli-Fruits-Bazar 1.0 is vulnerable to SQL Injection in /show_price_by_pdtId.php. Mitigation only Fix from $2,3002026-07-30 CRITICAL 9.8 CVE-2026-67594 Spikster through commit e1cdf8c contains a missing authentication vulnerability that allows unauthenticated remote attackers to access all API routes… No fix yet Fix from $2,3002026-07-30 MEDIUM 5.7 CVE-2026-67550 re2 provides Node.js bindings for Google's RE2 regular expression engine. Prior to 1.25.2, re2 validates lastIndex against the UTF-8 byte length of a… Patch available Fix from $1,6002026-07-30 MEDIUM 6.4 CVE-2026-67530 WACRM is a self-hostable CRM template for WhatsApp. In 0.7.0 and earlier, the automation send_webhook action in src/lib/automations/engine.ts and its… Patch available Fix from $1,6002026-07-30 HIGH 7.6 CVE-2026-67527 OpenProject is open-source, web-based project management software. Prior to 17.6.0, PATCH /api/v3/work_packages/{id} accepted _links.fileLinks and al… Patch available Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-67208 Juggle through 1.6.0 contains a remote code execution vulnerability that allows unauthenticated remote attackers to execute arbitrary OS commands by … No fix yet Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-67207 Wolf CMS through 0.8.3.1 contains an authorization bypass vulnerability in BackupRestoreController that allows authenticated non-administrative users… Mitigation only Fix from $1,9502026-07-30 HIGH 8.8 CVE-2026-67206 Wolf CMS through 0.8.3.1 contains a remote code execution vulnerability in FileManagerController that allows authenticated attackers to create arbitr… No fix yet Fix from $1,9502026-07-30 CRITICAL 9.8 CVE-2026-66756 Improper Protection of Alternate Path vulnerability in Apache Tika. This issue affects Apache Tika: from 4.0.0-alpha-1 before 4.0.0-beta-1. Users a… Tika No fix yet Fix from $2,3002026-07-30 HIGH 7.5 CVE-2026-66755 Relative Path Traversal in the ISA-Tab parser in Apache Software Foundation Apache Tika from 1.8 through 3.3.1, and 4.0.0-alpha-1, allows an attacker… Tika 3.3.2+ Fix from $1,9502026-07-30 MEDIUM 6.6 CVE-2026-65835 Capsule is a multi-tenancy and policy-based framework for Kubernetes. From 0.13.0 until 0.13.8, after the incomplete CVE-2026-22872 fix, TenantResour… No fix yet Fix from $1,6002026-07-30 MEDIUM 6.8 CVE-2026-65834 Capsule is a multi-tenancy and policy-based framework for Kubernetes. Prior to 0.13.8, CapsuleConfiguration.Spec.NodeMetadata.ForbiddenLabels.Regex a… No fix yet Fix from $1,6002026-07-30 CRITICAL 9.9 CVE-2026-12946 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input… Langflow 1.10.1+ Fix from $2,3002026-07-30 HIGH 8.5 CVE-2026-11536 IBM WebSphere Application Server 9.0, and 8.5 is affected by a remote code execution vulnerability in the SOAP/JMX connector. Websphere Application Server 8.5.5.29 / 9.0.5.28+ Fix from $1,9502026-07-30 MEDIUM 6.1 CVE-2025-51684 CleverTap Web SDK v1.15.1 is vulnerable to Cross Site Scripting (XSS). The application does not sanitize untrusted data received via window.postMessa… No fix yet Fix from $1,6002026-07-30 HIGH 8.8 CVE-2026-66416 Leantime 3.6.2 contains a cross-site request forgery vulnerability that allows unauthenticated attackers to perform state-changing actions on behalf … Patch available Fix from $1,9502026-07-30 HIGH 8.5 CVE-2026-66415 Leantime 3.6.2 contains a server-side request forgery and local file inclusion vulnerability that allows authenticated attackers to read internal res… Patch available Fix from $1,9502026-07-30 CRITICAL 9.5 CVE-2026-66066 Action Pack is a framework for handling and responding to web requests. In versions prior to 7.2.3.2, 8.0.5.1 and 8.1.3.1, Active Storage does not di… Patch available Fix from $2,3002026-07-30 MEDIUM 5.3 CVE-2026-64870 MaxKB is an open-source AI assistant for enterprise. In versions 2.0.0 through 2.10.4-lts, UpdateStoreTool.update_tool passes caller-supplied downloa… Patch available Fix from $1,6002026-07-30 HIGH 7.5 CVE-2026-61536 Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JSON objects from the rendered… No fix yet Fix from $1,9502026-07-30 MEDIUM 6.9 CVE-2026-59881 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.2, the WebSocket client accepts and decompresses frames… Patch available Fix from $1,6002026-07-30 CRITICAL 9.8 CVE-2026-51272 In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vulnerability exists in the latinToUTF8() character encoding conversion function. … No fix yet Fix from $2,3002026-07-30 CRITICAL 9.3 CVE-2026-48499 Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code piece sandbox can let an aut… Patch available Fix from $2,3002026-07-30 HIGH 8.8 CVE-2026-18245 Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticated user to execute arbitrar… Amplify Codegen Ui 2.20.6+ Fix from $1,9502026-07-30