Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.7 CVE-2026-15810 A Cross-Site Scripting (XSS) vulnerability in Google Cloud Looker versions prior to 25.6.103, 25.12.65, 25.18.68, 26.0.66, 26.2.47, 26.4.36, 26.6.28,… No fix yet Fix from $1,9502026-07-24 HIGH 7.4 CVE-2026-15243 Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or reg… No fix yet Fix from $1,9502026-07-24 HIGH 8.5 CVE-2026-10610 Local privilege escalation potentially allowed an attacker to execute arbitrary code as a privileged user. No fix yet Fix from $1,9502026-07-24 HIGH 8.5 CVE-2026-7483 Local privilege escalation potentially allowed an attacker to write an arbitrary file with fully controlled content as a privileged user. No fix yet Fix from $1,9502026-07-24 CRITICAL 9.8 CVE-2026-16634 TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99. The tomlc99 library is no longer maintained, and has… Mitigation only Fix from $2,3002026-07-24 HIGH 7.2 CVE-2026-15401 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'vbfX' parameter in all versions … No fix yet Fix from $1,9502026-07-24 HIGH 7.3 CVE-2026-10033 The EventON Action User plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.5.14. This is due to the p… No fix yet Fix from $1,9502026-07-24 MEDIUM 5.6 CVE-2026-63317 Arbitrary Class Instantiation via XML Feature Generator Descriptor and Format Name in Apache OpenNLP Versions Affected: - before 2.5.10 - before 3… Opennlp 2.5.11+ Fix from $1,6002026-07-24 HIGH 7.8 CVE-2026-49745 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's… Ddk 26.1+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-49744 Kernel software installed and running inside a Guest VM may post improper commands to the GPU Firmware to trigger a write of data outside the Guest's… Ddk 26.1+ Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-49743 Software installed and run as a non-privileged user may conduct improper GPU system calls to manipulate the lifetimes of synchronisation objects in t… Ddk 26.1+ Fix from $1,9502026-07-24 CRITICAL 9.3 CVE-2026-24727 An unrestricted upload of file with dangerous type vulnerability in the e-paper draft upload function of SUNNET Corporate Training Management System … No fix yet Fix from $2,3002026-07-24 MEDIUM 6.4 CVE-2026-15821 The SureDash – Community, Courses & Member Dashboard plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in al… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15739 The Rich Showcase for Google Reviews plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'pagination' Shortcode Attribute in all ve… No fix yet Fix from $1,6002026-07-24 CRITICAL 9.8 CVE-2026-15704 In Eclipse BaSyx Go Components versions up to and including 1.0.0, ABAC-enabled deployments are vulnerable to an authorization bypass caused by incon… Patch available Fix from $2,3002026-07-24 MEDIUM 6.1 CVE-2026-15346 The VikBooking Hotel Booking Engine & PMS plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'category_id' parameter in all… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.1 CVE-2026-12702 In affected versions of Octopus Deploy Insufficient checks on the project trigger actions allows an unauthorized user to trigger a deployment. No fix yet Fix from $1,6002026-07-24 MEDIUM 5.5 CVE-2026-16910 A flaw was found in Red Hat Quay's notification webhook feature. The Slack and generic webhook notification handlers accept user-supplied URLs withou… No fix yet Fix from $1,6002026-07-24 HIGH 7.3 CVE-2026-16519 A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Utility desktop application. The application loads one or more dynamic-link librar… No fix yet Fix from $1,9502026-07-24 MEDIUM 6.4 CVE-2026-15755 The Open User Map – Interactive Leaflet Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versio… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15665 The Fluent Support – Helpdesk & Customer Support Ticket System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'redirect-to' Sh… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15653 The Visualizer – Tables & Charts Manager with Built-in AI Generator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'backen… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15648 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'width' Shortcode Attribute in all versions up to, a… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15464 The WP Hotel Booking plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'widget_search' Shortcode Attribute in all versions up to,… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15334 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros… No fix yet Fix from $1,6002026-07-24 MEDIUM 6.4 CVE-2026-15333 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 600+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to Stored Cros… No fix yet Fix from $1,6002026-07-24 MEDIUM 5.3 CVE-2026-12654 The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.7. Th… No fix yet Fix from $1,6002026-07-24 HIGH 7.5 CVE-2026-14603 The WowOptin: Next-Gen Popup Maker WordPress plugin before 1.4.38 does not have proper authorization on a REST endpoint, allowing unauthenticated us… No fix yet Fix from $1,9502026-07-24 HIGH 7.8 CVE-2026-14172 Rapid7 InsightVM, Nexpose, and the Insight Agent execute discovered executables during authenticated assessment without validating file ownership, al… No fix yet Fix from $1,9502026-07-24 HIGH 7.5 CVE-2026-12981 The CAFEHAUS API WordPress plugin through 1.0.0 does not have any authentication or authorisation when updating user passwords, allowing unauthentica… No fix yet Fix from $1,9502026-07-24