Vulnerability index

Browse CVEs

930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Incorrect Privilege AssignmentCWE-266 × clear
CRITICAL 9.8 CVE-2026-66662 Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions. No fix yet Fix from $2,3002026-08-06 HIGH 7.2 CVE-2026-65559 Shop manager Privilege Escalation in Order Delivery Date for WooCommerce <= 4.6.0 versions. No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-65507 Unauthenticated Privilege Escalation in AIWU <= 1.5.6 versions. No fix yet Fix from $2,3002026-08-06 HIGH 8.8 CVE-2026-28111 Contributor Privilege Escalation in Forminator <= 1.56.0 versions. No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-19005 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/cre… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19007 A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/a… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18998 A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.t… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18996 A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCo… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18993 A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18976 A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.0 CVE-2026-20028 A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules tha… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-17626 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based… Langflow 1.11.0+ Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-10059 A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp… No fix yet Fix from $2,3002026-08-05 MEDIUM 6.3 CVE-2026-18723 A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-… No fix yet Fix from $1,6002026-08-04 MEDIUM 5.3 CVE-2026-18720 A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of t… No fix yet Fix from $1,6002026-08-04 HIGH 7.8 CVE-2026-18606 A weakness has been identified in Razer RzUpdateService 1.10.14.0. Affected by this vulnerability is an unknown functionality of the file C:\Program … No fix yet Fix from $1,9502026-08-03 MEDIUM 5.4 CVE-2026-18584 A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of … No fix yet Fix from $1,6002026-08-03 MEDIUM 6.3 CVE-2026-17434 A flaw has been found in nanocoai NanoClaw up to 2.0.64. Affected is the function handleAddMcpServer of the file src/modules/self-mod/request.ts of t… No fix yet Fix from $1,6002026-07-26 MEDIUM 5.3 CVE-2026-17433 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. This impacts the function createChatSdkBridge.setup of the file src/channels/chat-sdk… No fix yet Fix from $1,6002026-07-26 MEDIUM 5.0 CVE-2026-17432 A vulnerability was detected in NousResearch hermes-agent 2026.6.5. Affected by this vulnerability is an unknown functionality of the file hermes-age… No fix yet Fix from $1,6002026-07-26 MEDIUM 6.3 CVE-2026-16764 A vulnerability was identified in OWASP DefectDojo 2.59.0. This issue affects the function UserSerializer of the file dojo/api_v2/serializers.py of t… No fix yet Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-61951 Unauthenticated Privilege Escalation in TrueBooker <= 1.2.3 versions. No fix yet Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-59540 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.6 versions. No fix yet Fix from $2,3002026-07-23 HIGH 8.8 CVE-2026-59541 Subscriber Privilege Escalation in WP BASE Booking <= 6.3.1 versions. Mitigation only Fix from $1,9502026-07-23 HIGH 8.0 CVE-2026-47237 Kubeflow Community Distribution helps users to install Kubeflow Platform in popular Kubernetes clusters. Prior to version 26.03-rc.1, a Kubeflow setu… No fix yet Fix from $1,9502026-07-21 HIGH 8.8 CVE-2026-21824 HCL Commerce contains an privilege escalation vulnerability that could allow denial of service, disclosure of user personal data, and performing of u… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.3 CVE-2026-16199 A flaw has been found in nextlevelbuilder GoClaw up to 3.13.3-beta.3. This affects the function ExecTool.Execute of the file goclaw/internal/tools/cr… No fix yet Fix from $1,6002026-07-19 MEDIUM 6.3 CVE-2026-16121 A vulnerability was identified in nextlevelbuilder GoClaw up to 3.13.2. Affected is the function isSafeBin of the file internal/tools/exec_approval.g… No fix yet Fix from $1,6002026-07-18 CRITICAL 9.3 CVE-2026-50562 FastGPT is a knowledge-based AI application platform. At commit 22ebfacbb43311e9b73294040ae0eb87390c6bba and earlier, artifacts built from untrusted … Mitigation only Fix from $2,3002026-07-15 CRITICAL 9.8 CVE-2026-57813 Incorrect Privilege Assignment vulnerability in properfraction MailOptin mailoptin allows Privilege Escalation.This issue affects MailOptin: from n/a… Mitigation only Fix from $2,3002026-07-13