Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.9
CVE-2026-77710

A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX imp…

Patch available
Fix from $4,000 2026-08-21
Unclassified HIGH 8.1
CVE-2026-68745

Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.2
CVE-2026-66722

Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can crea…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.8
CVE-2026-74866

@fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-retur…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2026-66797

Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listA…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.8
CVE-2026-63046

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager ex…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-62440

Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cl…

Fix unknown
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-61398

Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affect…

Fix unknown
Fix from $5,750 2026-08-21
Unclassified HIGH 7.5
CVE-2026-61397

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integra…

Fix unknown
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-61400

Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics func…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-59780

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP provide…

Fix unknown
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-59657

Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache Cloud…

Fix unknown
Fix from $4,900 2026-08-21
Unclassified HIGH 7.5
CVE-2026-59655

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth provi…

Fix unknown
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.1
CVE-2026-59085

Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affect…

Fix unknown
Fix from $5,750 2026-08-21
Unclassified HIGH 7.5
CVE-2026-50222

Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Seve…

Fix unknown
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-59799

Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication …

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-50112

SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing…

No fix yet
Fix from $4,900 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas…

No fix yet
Fix from $5,750 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-19441

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: thr…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.5
CVE-2026-16323

Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.2
CVE-2026-75796

The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing …

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.1
CVE-2026-18781

The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after …

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-16962

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail ret…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.8
CVE-2026-16959

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its …

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.2
CVE-2026-16576

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-16575

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission …

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 6.8
CVE-2026-14601

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authen…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.3
CVE-2026-13736

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route,…

No fix yet
Fix from $4,000 2026-08-21
Unclassified MEDIUM 5.4
CVE-2025-15671

The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier fr…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.2
CVE-2026-18409

The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all version…

No fix yet
Fix from $4,900 2026-08-21