Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-67217 cJSON through 1.7.19 applies RFC 6902 JSON Patch operations non-atomically in apply_patch() in cJSON_Utils.c. For a replace operation that is missing… Cjson after 1.7.19 Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-67216 cJSON through 1.7.19 contains an inefficient algorithmic complexity flaw in cJSON_Compare(). When comparing objects, the function recurses into each … Cjson after 1.7.19 Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-67215 cJSON through 1.7.19 is vulnerable to uncontrolled recursion leading to stack exhaustion when an untrusted RFC 6902 JSON Patch is applied via cJSONUt… Cjson after 1.7.19 Fix from $1,9502026-07-29 HIGH 7.5 CVE-2026-67214 nanoid (Nano ID) before 3.3.16 and 5.1.16 contains an infinite loop in the customAlphabet and nanoid functions of its non-secure module (nanoid/non-s… Nanoid 5.1.16+ Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-66489 Joomla Extension - balbooa.com - Various unauthenticated file system disclosure in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,6002026-07-29 MEDIUM 5.3 CVE-2026-66488 Joomla Extension - balbooa.com - Payment bypass in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-67213 nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customAlphabet and customRandom functions. When these functions are configured with a … Nanoid 3.3.17 / 5.1.6+ Fix from $1,9502026-07-29 MEDIUM 6.1 CVE-2026-66490 Joomla Extension - balbooa.com - Stored cross-site scripting via a comment avatar in Gridbox < 2.20.2 Gridbox 2.20.2+ Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-65890 Joomla Extension - balbooa.com - Unauthenticated SQL injection in Gridbox < 2.20.2 - Multiple SQLi vectors allow unauthenticated actors to inject SQL… Gridbox 2.20.2+ Fix from $2,3002026-07-29 HIGH 7.5 CVE-2026-65889 Joomla Extension - balbooa.com - Unauthenticated recursive directory deletion < 2.20.2 - The generateNewApp method allows actors to recursively delet… Gridbox 2.20.2+ Fix from $1,9502026-07-29 HIGH 8.7 CVE-2026-55995 A Double Free vulnerability in open-iscsi allows an unauthenticated MITM attacker to cause DoS. This issue affects open-iscsi: from ? through 5… Patch available Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-16751 Authorization Bypass in the emergency recovery approval component in Ente Technologies Ente Museum Server allows an authenticated attacker configured… No fix yet Fix from $1,6002026-07-29 MEDIUM 5.3 CVE-2026-18174 @fastify/forwarded resolves client addresses from the X-Forwarded-For header. In versions before 3.0.2, when the header contains two or more comma se… Fastify\/forwarded 3.0.2+ Fix from $1,6002026-07-29 HIGH 8.8 CVE-2026-65944 Joomla Extension - rolandd.com - CSRF vectors in AJAX endpoint handlers RO CSVI < 9.11.0 Ro Csvi 9.11.0+ Fix from $1,9502026-07-29 MEDIUM 6.1 CVE-2026-65946 Joomla Extension - rolandd.com - XSS vectors in AJAX endpoint handlers RO CSVI < 9.11.0 Ro Csvi 9.11.0+ Fix from $1,6002026-07-29 HIGH 7.5 CVE-2026-65943 Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0 Ro Csvi 9.11.0+ Fix from $1,9502026-07-29 MEDIUM 6.5 CVE-2026-65891 Joomla Extension - joomlacontenteditor.net - Creation of hidden files and unintended file overwrite via rename function in Joomla Content Editor (JCE… Jce 2.20.2+ Fix from $1,6002026-07-29 HIGH 8.8 CVE-2026-65885 Joomla Extension - balbooa.com - Authenticated arbitrary file upload in Gridbox < 2.20.2 - File upload methods allows authenticated attackers to uplo… Gridbox 2.20.2+ Fix from $1,9502026-07-29 CRITICAL 9.8 CVE-2026-65884 Joomla Extension - balbooa.com - Privilege Escalation in Gridbox < 2.20.2 - The registration method allows users provided usergroup IDs, allowing una… Gridbox 2.20.2+ Fix from $2,3002026-07-29 HIGH 7.1 CVE-2026-50641 Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were … No fix yet Fix from $1,9502026-07-29 HIGH 8.5 CVE-2026-44944 An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket. This issue affects… Patch available Fix from $1,9502026-07-29 MEDIUM 6.9 CVE-2026-44943 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create… Patch available Fix from $1,6002026-07-29 MEDIUM 5.1 CVE-2026-33385 A Blind SQL injection vulnerability has been identified in Quick.CMS. Improper neutralization of input provided by a high-privileged user into multip… No fix yet Fix from $1,6002026-07-29 HIGH 8.7 CVE-2026-14354 CWE-522 Insufficiently Protected Credentials vulnerability exists that could cause authentication bypass and unauthorized credential modification, po… No fix yet Fix from $1,9502026-07-29 HIGH 8.4 CVE-2026-12927 CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.3 CVE-2026-0667 CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability that could cause arbitrary code execution, denial of service and loss of … No fix yet Fix from $2,3002026-07-29 HIGH 8.8 CVE-2026-14270 The Extra Checkout Options (addon for Extra Product Options & Add-Ons for WooCommerce) plugin for WordPress is vulnerable to Arbitrary File Upload in… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.4 CVE-2026-8791 The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.4 CVE-2026-7436 The WPC Badge Management for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'text' attribute of the `wpcbm_bes… No fix yet Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-65883 Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP o… Aimy Captcha Less Form Guard after 20.0 Fix from $2,3002026-07-29