Published vulnerability pages
Website Security Risk Index — Page 30
Current vulnerabilities, affected platforms, and fix guidance for website owners and developers.
Browse by topic
Security risk categories
46 categories with published guidance
Memory Corruption
409Browse published Memory Corruption vulnerabilities, affected products, and practical fix guidance.
Authorization Bypass
373Browse published Authorization Bypass vulnerabilities, affected products, and practical fix guidance.
WordPress
350Browse published WordPress vulnerabilities, affected products, and practical fix guidance.
Information Disclosure
320Browse published Information Disclosure vulnerabilities, affected products, and practical fix guidance.
Remote Code Execution
303Browse published Remote Code Execution vulnerabilities, affected products, and practical fix guidance.
Cross-site Scripting
260Browse published Cross-site Scripting vulnerabilities, affected products, and practical fix guidance.
Network Security
253Browse published Network Security vulnerabilities, affected products, and practical fix guidance.
Input Validation
243Browse published Input Validation vulnerabilities, affected products, and practical fix guidance.
Web Application
239Browse published Web Application vulnerabilities, affected products, and practical fix guidance.
Windows
216Browse published Windows vulnerabilities, affected products, and practical fix guidance.
API Security
215Browse published API Security vulnerabilities, affected products, and practical fix guidance.
Browser
215Browse published Browser vulnerabilities, affected products, and practical fix guidance.
Denial of Service
215Browse published Denial of Service vulnerabilities, affected products, and practical fix guidance.
Microsoft
212Browse published Microsoft vulnerabilities, affected products, and practical fix guidance.
PHP
199Browse published PHP vulnerabilities, affected products, and practical fix guidance.
Path Traversal
167Browse published Path Traversal vulnerabilities, affected products, and practical fix guidance.
Authentication Bypass
118Browse published Authentication Bypass vulnerabilities, affected products, and practical fix guidance.
Arbitrary File Write
116Browse published Arbitrary File Write vulnerabilities, affected products, and practical fix guidance.
Privilege Escalation
113Browse published Privilege Escalation vulnerabilities, affected products, and practical fix guidance.
Linux
94Browse published Linux vulnerabilities, affected products, and practical fix guidance.
DevOps
81Browse published DevOps vulnerabilities, affected products, and practical fix guidance.
SQL Injection
72Browse published SQL Injection vulnerabilities, affected products, and practical fix guidance.
Cryptography
68Browse published Cryptography vulnerabilities, affected products, and practical fix guidance.
SSRF
61Browse published SSRF vulnerabilities, affected products, and practical fix guidance.
Python
59Browse published Python vulnerabilities, affected products, and practical fix guidance.
Java
57Browse published Java vulnerabilities, affected products, and practical fix guidance.
IDOR
56Browse published IDOR vulnerabilities, affected products, and practical fix guidance.
WooCommerce
53Browse published WooCommerce vulnerabilities, affected products, and practical fix guidance.
Unsafe Deserialization
51Browse published Unsafe Deserialization vulnerabilities, affected products, and practical fix guidance.
File Upload
47Browse published File Upload vulnerabilities, affected products, and practical fix guidance.
npm
44Browse published npm vulnerabilities, affected products, and practical fix guidance.
Joomla
41Browse published Joomla vulnerabilities, affected products, and practical fix guidance.
Supply Chain
39Browse published Supply Chain vulnerabilities, affected products, and practical fix guidance.
Cloud Security
36Browse published Cloud Security vulnerabilities, affected products, and practical fix guidance.
CSRF
33Browse published CSRF vulnerabilities, affected products, and practical fix guidance.
Race Condition
31Browse published Race Condition vulnerabilities, affected products, and practical fix guidance.
PDF Editor
28Browse published PDF Editor vulnerabilities, affected products, and practical fix guidance.
Industrial Control
27Browse published Industrial Control vulnerabilities, affected products, and practical fix guidance.
.NET
23Browse published .NET vulnerabilities, affected products, and practical fix guidance.
File Deletion
23Browse published File Deletion vulnerabilities, affected products, and practical fix guidance.
Open Redirect
16Browse published Open Redirect vulnerabilities, affected products, and practical fix guidance.
Node.js
15Browse published Node.js vulnerabilities, affected products, and practical fix guidance.
SAML
13Browse published SAML vulnerabilities, affected products, and practical fix guidance.
Virtualization
13Browse published Virtualization vulnerabilities, affected products, and practical fix guidance.
Drupal
6Browse published Drupal vulnerabilities, affected products, and practical fix guidance.
Unix Domain Sockets
5Browse published Unix Domain Sockets vulnerabilities, affected products, and practical fix guidance.
Published security risks
Showing 1045–1080 of 2230 published risks.
CVE-2026-55810 in Drupal Plotly.js Graphing
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Plotly.js Graphing allows Object Injection. This issue affects Plotly.js Graphing versions: from 0.0.0 to 3.0.2.
Updated Jul 15, 2026
CVE-2026-58589 in Drupal FlowDrop
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Updated Jul 15, 2026
CVE-2026-58590 in Drupal FlowDrop
Missing Authorization vulnerability in Drupal FlowDrop allows Forceful Browsing. This issue affects FlowDrop versions: from 0.0.0 to 1.6.0.
Updated Jul 15, 2026
CVE-2026-58591 in Drupal Colorbox
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox allows Cross-Site Scripting (XSS). This issue affects Colorbox versions: from 0.0.0 to 2.1.5, from 0.0.0 to 2.2.0.
Updated Jul 15, 2026
CVE-2026-59835 in FortiSandbox
A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests.
Updated Jul 15, 2026
CVE-2026-59836 in FortiClient EMS
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
Updated Jul 15, 2026
CVE-2026-59837 in FortiProxy
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions,...
Updated Jul 15, 2026
CVE-2026-59839 in FortiProxy
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM...
Updated Jul 15, 2026
CVE-2026-59840 in FortiProxy
A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiProxy 7.6.0 through 7.6.5, FortiProxy 7.4.0 through 7.4.13, FortiProxy 7.2 all versions may allow attacker to information...
Updated Jul 15, 2026
CVE-2026-50522 in Microsoft SharePoint Server
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Updated Jul 15, 2026
CVE-2026-54108 in Microsoft SharePoint Server
External control of file name or path in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Updated Jul 15, 2026
CVE-2026-54433 in Roundcube Webmail
In Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2, there is Stored Cross-Site Scripting (XSS) via a crafted plain-text email message. The attacker-controlled JavaScript executes within the victim's authenticated session simply by opening or...
Updated Jul 15, 2026
CVE-2026-58644 in Microsoft SharePoint Server
Deserialization of untrusted data in Microsoft Office SharePoint allows an unauthorized attacker to execute code over a network.
Updated Jul 15, 2026
CVE-2026-45074 in Symfony Security HTTP
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.1.0 until 7.4.12 and 8.0.12, Cas2Handler builds the CAS service parameter from Request::getSchemeAndHttpHost(), which reflects an attacker-controlled...
Updated Jul 15, 2026
CVE-2026-45077 in Symfony Monolog Bridge
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the server:log listener (Symfony\Bridge\Monolog\Command\ServerLogCommand) binds to 0.0.0.0:9911 by default and...
Updated Jul 15, 2026
CVE-2026-45756 in Symfony JSON Path
Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match()...
Updated Jul 15, 2026
CVE-2026-55016 in Microsoft SharePoint Server
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Updated Jul 15, 2026
CVE-2026-55019 in Microsoft SharePoint Server
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Updated Jul 15, 2026
CVE-2026-55020 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55021 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55030 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55034 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55135 in Microsoft SharePoint Server
Microsoft SharePoint Server has a cross-site scripting issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-55947 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-55949 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has an uninitialized resource issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-56156 in Microsoft Excel / Microsoft 365 Apps
Microsoft Excel has a memory corruption issue that can let an attacker run code when a user opens a malicious file.
Updated Jul 15, 2026
CVE-2026-56157 in Microsoft SharePoint Server
Microsoft SharePoint Server has an access control issue that can let an authorized attacker spoof content over the network.
Updated Jul 15, 2026
CVE-2026-58277 in Microsoft SharePoint Server
Microsoft SharePoint Server has an authorization issue that can let an authorized attacker gain higher privileges over the network.
Updated Jul 15, 2026
CVE-2026-45063 in Symfony Security HTTP
Symfony Security HTTP can spoof a certificate identity when X509Authenticator parses a crafted DN.
Updated Jul 15, 2026
CVE-2026-45064 in Symfony HTML Sanitizer
Symfony HTML Sanitizer can leave visual-spoofing BiDi characters in sanitized URLs.
Updated Jul 15, 2026
CVE-2026-45069 in Symfony Security HTTP
Symfony Security HTTP can accept OIDC tokens that miss required audience, issuer, or expiry claims.
Updated Jul 15, 2026
CVE-2026-45070 in Symfony MIME
Symfony MIME can allow email header injection through unsafe MIME parameter names.
Updated Jul 15, 2026
CVE-2026-45073 in Symfony Cache
Symfony Cache can build unsafe SQL when an untrusted cache prefix reaches PdoAdapter clear.
Updated Jul 15, 2026
CVE-2026-45075 in Symfony Security HTTP
Symfony Security HTTP can let HEAD requests bypass checks that only allow GET requests.
Updated Jul 15, 2026
CVE-2026-45133 in Symfony YAML
Symfony YAML can crash a worker when it parses very deeply nested YAML input.
Updated Jul 15, 2026
CVE-2026-45304 in Symfony YAML
Symfony YAML can use too much memory when crafted aliases expand recursively.
Updated Jul 15, 2026
