Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-73073 Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr… Patch available Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-72532 Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow… No fix yet Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.7 CVE-2026-71477 mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1… Patch available Fix from $4,0002026-08-18 HIGH 7.7 CVE-2026-71365 A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.8 CVE-2026-63328 Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins wit… Patch available Fix from $4,0002026-08-18 HIGH 8.8 CVE-2026-62357 Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whos… Patch available Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-55839 Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link… Patch available Fix from $4,9002026-08-18 HIGH 7.6 CVE-2026-49227 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment opera… Patch available Fix from $4,9002026-08-18 HIGH 8.3 CVE-2026-49226 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operatio… Patch available Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-49221 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset… Patch available Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-46482 ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challe… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-45734 MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remot… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-45125 MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail h… Patch available Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-45120 MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w… Patch available Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-45118 MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-45117 MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura… Patch available Fix from $5,7502026-08-18 HIGH 8.7 CVE-2026-45116 MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field … Patch available Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-45115 MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-19500 The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or sub… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.0 CVE-2026-15806 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d… Patch available Fix from $4,0002026-08-18 CRITICAL 9.6 CVE-2026-12564 A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r… No fix yet Fix from $5,7502026-08-18 HIGH 8.5 CVE-2026-75898 RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The … Patch available Fix from $4,9002026-08-18 MEDIUM 6.9 CVE-2026-75872 HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send … Patch available Fix from $4,0002026-08-18 CRITICAL 10.0 CVE-2026-75784 A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx … No fix yet Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile … No fix yet Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-74015 Unauthenticated SQL Injection in Readabler < 2.0.18 versions. No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-74012 Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. No fix yet Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-74009 Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-74008 Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. No fix yet Fix from $4,0002026-08-18