Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 10.0
CVE-2026-77946

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/app…

No fix yet
Fix from $5,750 2026-08-22
Unclassified HIGH 7.4
CVE-2026-77945

A vulnerability was found in TRENDnet TEW-821DAP 2.2.01b05. Affected is an unknown function of the file /cgi-bin/upload.cgi of the component ssi. Per…

No fix yet
Fix from $4,900 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-78003

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.3
CVE-2026-12710

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or no…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77000

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before…

No fix yet
Fix from $5,750 2026-08-22
Unclassified HIGH 8.1
CVE-2026-76793

The Firebase Authentication WordPress plugin before 1.7.1 does not require the email address in an authentication token to be verified before matchin…

No fix yet
Fix from $4,900 2026-08-22
Unclassified HIGH 8.8
CVE-2026-76789

The Slider Hero with Video Background, Animation WordPress plugin before 9.1.3 does not have authorisation and nonce checks on two of its request han…

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.6
CVE-2026-19222

The Forminator Forms WordPress plugin before 1.57.0.7 does not consistently enforce the role restriction it applies to registration forms, allowing …

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 7.2
CVE-2026-19221

The Forminator Forms WordPress plugin before 1.57.0.5 does not restrict a network-wide setting to network administrators, allowing an administrator …

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 6.8
CVE-2026-19093

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allowing users with the instructor…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 8.1
CVE-2026-18052

The ManageWP Worker WordPress plugin before 4.9.37 does not bind the account being logged in to the signature which authorises the login, nor prevent…

No fix yet
Fix from $4,900 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-16738

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway webhook notifications, nor bin…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-16612

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauthenticated AJAX endpoints, all…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 6.8
CVE-2026-16260

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom post type settings before out…

No fix yet
Fix from $4,000 2026-08-22
Unclassified MEDIUM 5.3
CVE-2026-75027

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8.0. This is due to the plugin…

No fix yet
Fix from $4,000 2026-08-22
Unclassified HIGH 8.8
CVE-2026-19883

The WPeMatico RSS Feed Fetcher plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a…

Patch available
Fix from $4,900 2026-08-22
Unclassified HIGH 7.4
CVE-2026-53525

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 0.3.1 through 4.9.0, the WeeChat relay authentication uses non-constan…

No fix yet
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-53524

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay module's WebSocket permessage-d…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.2
CVE-2026-53499

FORT Validator is a Resource Public Key Infrastructure (RPKI) relying-party validator that produces validated route-origin data. FORT Validator versi…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 7.8
CVE-2026-49360

Recce is a data-validation toolkit for enhanced dbt (data build tool) PR review. Prior to version 1.50.0, OSS server deployments that expose the serv…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.3
CVE-2026-48106

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's cluster replication receiver at `internal/c…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.3
CVE-2026-48105

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc Enterprise's Raft FSM (`internal/cluster/raft/fsm.go:app…

No fix yet
Fix from $4,900 2026-08-21
Unclassified HIGH 8.8
CVE-2026-48050

Arc is an open, SQL-native time-series database for telemetry. Versions prior to 26.06.1 register Go's `net/http/pprof` handlers at `/debug/pprof/*` …

Patch available
Fix from $4,900 2026-08-21
Unclassified HIGH 7.1
CVE-2026-47735

Arc is an open, SQL-native time-series database for telemetry. Prior to version 26.06.1, Arc's user-SQL validator (`internal/api/query.go:ValidateSQL…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.5
CVE-2026-34949

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonly file on iTop instances — a …

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 7.7
CVE-2026-34948

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, only classes present in the SELECT clause are protected by the silos access c…

Patch available
Fix from $4,900 2026-08-21
Unclassified MEDIUM 6.9
CVE-2026-53531

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, RaTeX’s recursive-descent parser recurses one (or more) n…

No fix yet
Fix from $4,000 2026-08-21
Unclassified HIGH 8.7
CVE-2026-53530

RaTeX is a KaTeX-compatible math rendering engine written in Rust. Prior to version 0.1.11, the public parser entrypoint `ratex_parser::parse(&str)` …

No fix yet
Fix from $4,900 2026-08-21