Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.9
CVE-2026-59296

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-15576

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate …

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.3
CVE-2026-14208

Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), …

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77755

A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code u…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-77751

A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object nam…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-77681

A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/upda…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-59323

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded ob…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-47827

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vul…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-77710

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX imp…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.8
CVE-2026-74866

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-retur…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2026-66797

Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listA…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.8
CVE-2026-63046

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager ex…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-61400

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics func…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-50112

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas…

No fix yet
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-19441

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: thr…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-16323

Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.2
CVE-2026-75796

The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing …

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.1
CVE-2026-18781

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after …

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-16962

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail ret…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.8
CVE-2026-16959

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its …

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.2
CVE-2026-16576

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-16575

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.8
CVE-2026-14601

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authen…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-13736

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route,…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2025-15671

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier fr…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.2
CVE-2026-18409

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all version…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-76158

External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacke…

No fix yet
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-76131

Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.7
CVE-2026-73267

A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete Clus…

No fix yet
Fix from $4,900 2026-08-21