Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.6
CVE-2026-62381

luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the native ASN.1 encoding routine asn1_add_obj (x509write.c) when signing a certificate…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 6.3
CVE-2026-62380

Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16.Final and 4.1.x through 4.1.136.Final contain null byte, CRLF, and credential …

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 7.5
CVE-2026-62243

Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.16.Final and versions through 4.1.136.Final disable TLS hostname verification on…

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.6
CVE-2026-62204

SiYuan versions before v3.7.4 fail to validate that packageName matches the downloaded package content in bazaar install endpoints. Attackers with sa…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 8.7
CVE-2026-60084

SiYuan versions before v3.7.4 contain an arbitrary file deletion vulnerability in the /api/search/removeTemplate endpoint that accepts an unvalidated…

No fix yet
Fix from $4,900 2026-08-22
Unclassified HIGH 8.8
CVE-2026-59808

AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials …

No fix yet
Fix from $4,900 2026-08-22
Unclassified HIGH 7.5
CVE-2026-59256

WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity o…

No fix yet
Fix from $4,900 2026-08-22
Unclassified HIGH 7.1
CVE-2026-58003

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authentic…

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.5
CVE-2026-58002

WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.7
CVE-2026-58001

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 7.8
CVE-2026-57998

better-npm-audit through 3.11.0, and the 4.0.0-rc.2 prerelease, builds its npm audit command by interpolating the user-supplied --registry option int…

Patch available
Fix from $4,900 2026-08-22
Unclassified MEDIUM 5.4
CVE-2026-57944

AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-56380

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve cha…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 6.6
CVE-2026-77988

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. This vulnerability affects the function nvram_get of the component CLI Configuration…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 8.6
CVE-2026-66917

Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery < 4.4.0 - An authenticated, privileged can store an XSS payload in any image ca…

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.9
CVE-2026-66916

Joomla Extension - joomgalleryfriends.net - Password-Protected Category Bypass via JSON Format in JoomGallery < 4.4.0- An unauthenticated access cont…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-3424

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up t…

No fix yet
Fix from $4,000 2026-08-22
Unclassified CRITICAL 10.0
CVE-2026-77946

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/app…

No fix yet
Fix from $5,750 2026-08-22
Unclassified HIGH 7.4
CVE-2026-77945

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Per…

No fix yet
Fix from $4,900 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-78003

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.3
CVE-2026-12710

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or no…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77000

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before…

No fix yet
Fix from $5,750 2026-08-22
Unclassified HIGH 8.1
CVE-2026-76793

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matchin…

No fix yet
Fix from $4,900 2026-08-22
Unclassified HIGH 8.8
CVE-2026-76789

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request han…

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.6
CVE-2026-19222

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing …

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 7.2
CVE-2026-19221

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator …

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.8
CVE-2026-19093

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 8.1
CVE-2026-18052

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent…

No fix yet
Fix from $4,900 2026-08-22