Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.7
CVE-2026-77068

n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP nod…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.5
CVE-2026-74021

Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.5
CVE-2026-74020

Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-74019

Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-74018

Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-74016

Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-74014

Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.5
CVE-2026-74013

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-74001

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 8.5
CVE-2026-73998

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-73993

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.9
CVE-2026-73992

Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-73402

Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.

No fix yet
Fix from $4,000 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-68566

Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 7.1
CVE-2026-68564

Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-66682

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-66680

Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 7.6
CVE-2026-66677

Subscriber Broken Authentication in Leyka <= 3.32.3 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66673

Unauthenticated Cross Site Scripting (XSS) in Flatastic <= 2.0 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-66672

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-66649

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-66647

Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66616

Unauthenticated Cross Site Scripting (XSS) in Form Maker by 10Web <= 1.15.46 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66615

Unauthenticated Cross Site Scripting (XSS) in Podlove Podcast Publisher <= 4.5.4 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66614

Unauthenticated Cross Site Scripting (XSS) in SEO Plugin by Squirrly SEO <= 14.2.2 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66612

Unauthenticated Cross Site Scripting (XSS) in Aora <= 1.3.19 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66611

Unauthenticated Cross Site Scripting (XSS) in Paymob for WooCommerce <= 4.1.10 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-66609

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66607

Unauthenticated Cross Site Scripting (XSS) in Advance Product Search <= 1.4.8 versions.

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-66606

Unauthenticated Cross Site Scripting (XSS) in SmartSMTP <= 1.2.0 versions.

No fix yet
Fix from $4,900 2026-08-20