Vulnerability index

Browse CVEs

7,720 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Information ExposureCWE-200 × clear
Unclassified MEDIUM 5.3
CVE-2026-72549

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or u…

No fix yet
Fix from $4,000 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72539

An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace member to read legacy ownerless …

No fix yet
Fix from $4,000 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72915

Mastodon is a free, open-source social network server based on ActivityPub. From 4.6.0-beta.1 until 4.6.4 and 4.7.0-beta.1, any logged-in local user …

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72873

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/api/routers/application.ts re…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 6.5
CVE-2026-72726

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated user could eavesdrop on privat…

No fix yet
Fix from $4,000 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-72760

Affected versions of MISP cti-transmute disclose users' email addresses through the account following-list endpoint. When an authenticated user follo…

No fix yet
Fix from $4,000 2026-08-10
Tapestry HIGH 7.5
CVE-2026-61899

Vulnerability in tapestry-core in Apache Tapestry 5.5.0+ on all platforms allows attackers to download clsspath assets via specially crafted URLs. Us…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19074

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) is vulnerable to unauthenticat…

No fix yet
Fix from $4,000 2026-08-10
Unclassified HIGH 7.5
CVE-2026-18470

The Login & Register Forms WordPress plugin before 4.0.2 does not verify that a password reset request comes from the account's owner, and does not …

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-18946

The Contact Form to Any API WordPress plugin before 3.0.7 does not use a random filename when copying files uploaded through contact forms into a pub…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-17022

The Salon Booking System WordPress plugin before 10.30.34 does not properly validate a booking's ownership token before loading it in its booking-wi…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-17541

The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to re…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-17542

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any aut…

No fix yet
Fix from $4,900 2026-08-10
Unclassified HIGH 7.5
CVE-2026-14206

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing…

No fix yet
Fix from $4,900 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-19363

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handler.rs of the component Lambda…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19357

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form/get of the component ms-mdiy…

No fix yet
Fix from $4,000 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19356

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/data/list of the component ms-md…

No fix yet
Fix from $4,000 2026-08-09
Unclassified HIGH 7.5
CVE-2026-18357

The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allo…

No fix yet
Fix from $4,900 2026-08-09
Unclassified HIGH 7.5
CVE-2026-18032

The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the …

No fix yet
Fix from $4,900 2026-08-09
Unclassified HIGH 7.5
CVE-2026-16988

The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested list…

No fix yet
Fix from $4,900 2026-08-09
Unclassified MEDIUM 6.5
CVE-2026-16595

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing …

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-16562

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only o…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 7.5
CVE-2026-16578

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability che…

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-16590

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing …

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 7.5
CVE-2026-16594

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing …

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 8.6
CVE-2026-48007

Element Call is a native Matrix video conferencing application. Versions 0.5.17 through 0.19.3 report analytics data to a PostHog server, when config…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-47364

In versions of the Datadog Android application prior to v545-5.9.2, the app tags Crashlytics data with the user's Datadog UUID, with no user-facing o…

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-19229

A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of …

No fix yet
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-54203

Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessin…

No fix yet
Fix from $2,300 2026-08-07
Unclassified HIGH 7.5
CVE-2026-14943

The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API acc…

No fix yet
Fix from $1,950 2026-08-07