Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-16738

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bin…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-16612

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, all…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 6.8
CVE-2026-16260

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before out…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-75027

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 8.8
CVE-2026-19883

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a…

Patch available
Fix from $4,900 2026-08-22
Unclassified HIGH 7.4
CVE-2026-53525

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constan…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-53524

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-d…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.2
CVE-2026-53499

FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versi…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.8
CVE-2026-49360

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the serv…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.3
CVE-2026-48106

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/c…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.3
CVE-2026-48105

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:app…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-48050

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` …

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.1
CVE-2026-47735

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQL…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-34949

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a …

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.7
CVE-2026-34948

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access c…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-53531

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) n…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.7
CVE-2026-53530

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` …

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-53528

LeafWiki is a self-hosted wiki. Versions 0.3.0 through 0.10.0 have a path traversal vulnerability in LeafWiki’s asset rename functionality. An authen…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-53527

LeafWiki is a self-hosted wiki. Versions 0.1.0 through 0.10.0 have a privilege escalation vulnerability in the user update API. An authenticated user…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.7
CVE-2026-53509

CKAN MCP Server is a tool for querying CKAN open data portals. A known vulnerability CVE-2026-33060 indicated tools including ckan_package_search and…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-53497

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without authentication and returns the o…

No fix yet
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-49849

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administr…

Patch available
Fix from $5,750 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-43980

Malla is a web analyzer for Meshtastic networks based on MQTT data. Prior to commit 4086e2b5f61615a813b70b25bc76095083552135, code names (long_name, …

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-34836

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and ajax.document.php allows for d…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 8.6
CVE-2026-34741

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated remote attackers to execute arbi…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-33240

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, there was a Reflected Cross-Site Scripting (XSS) vulnerability in the foreign…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-31936

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, users can access to unauthorized object information through the search operat…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77811

Improper input validation in the dashboards-observability plugin in OpenSearch Dashboards allows a remote authenticated user with write permissions t…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77415

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weakn…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77414

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOw…

Patch available
Fix from $5,750 2026-08-21