Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.6
CVE-2026-76613

Joomla Extension - yootheme.com - Authenticated, privileged SQL injection in YOOtheme Pro 1.0.0-5.0.40 - An SQL injection allowed any contributor-lev…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.6
CVE-2026-76612

Joomla Extension - yootheme.com - Unauthenticated stored XSS via user-controlled fields in Zoo < 4.1.66 - User supplied input in comments and user su…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-76611

Joomla Extension - yootheme.com - Unauthenticated arbitrary directory listing via the Gallery element in Zoo < 4.1.66.

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.0
CVE-2026-75115

Joomla Extension - yootheme.com - Authenticated, privileged arbitrary file read in YOOtheme Pro 2.3.0-5.0.40 - The Filesystem source's path filter is…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.8
CVE-2026-59654

Missing Release of Resource after Effective Lifetime vulnerability in Apache CloudStack's scoped global configuration functionality. It affects diffe…

No fix yet
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-77776

Headroom's LLM proxy derives the memory owner from the x-headroom-user-id request header. The header is read directly at several points in headroom/p…

Patch available
Fix from $5,750 2026-08-21
Unclassified HIGH 8.6
CVE-2026-77775

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve_openai_upstream_base in head…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77759

Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user …

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-59318

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully enforced when a tool call is…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-59279

The MCP Streamable HTTP server transport (WebFlux and WebMvc variants) does not place any limit on the number of sessions it retains, and by default …

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-19848

The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before rendering them on public pages, allow…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-17559

The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which REST API requests may bypass gl…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-16650

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events in a default configuration, …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-15150

The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification matches the site's configured …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77769

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned getReportsByDashboardId(dashboar…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77768

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(reportId) directly. The enforceAc…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-77767

Reconmap's API applies a fallback authorization policy in apps/api/app/Program.cs that requires an authenticated user holding the administrator role,…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-77763

The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived every operation's target from …

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-77761

A parser state isolation vulnerability in misp-stix could cause data from a previously processed STIX document to be retained and incorporated into t…

Patch available
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2026-77686

A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handl…

Patch available
Fix from $4,000 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-77683

A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is the function system of the file /cgi-bin/mbox-config?method…

No fix yet
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-77086

SiYuan before v3.7.4 fails to validate the packageName parameter in Bazaar install and uninstall endpoints, allowing authenticated administrators to …

No fix yet
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.9
CVE-2026-59296

Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-15576

Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate …

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.3
CVE-2026-14208

Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), …

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.7
CVE-2026-77755

A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code u…

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-77751

A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object nam…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.3
CVE-2026-77681

A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/upda…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-59323

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded ob…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-47827

Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vul…

No fix yet
Fix from $4,900 2026-08-21