Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-75963

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-75860

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-74992

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does …

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-19697

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file …

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-19615

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allo…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-17153

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.2
CVE-2026-15049

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.6
CVE-2026-13405

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.9
CVE-2026-76956

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnera…

Patch available
Fix from $4,000 2026-08-20
Unclassified HIGH 7.8
CVE-2026-19582

In binutils 2.46.1 and prior versions, a victim who opens a crafted PE file using binutils could execute arbitrary code unknowningly via a stack buff…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-76800

A flaw has been found in DeDeCMS 3. Affected by this vulnerability is an unknown functionality of the file /include/dialog/select_media_post.php. Exe…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-76799

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/log…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.3
CVE-2026-76795

A vulnerability has been found in AeternaLabsHQ PullMD 3.2.0. This impacts an unknown function of the file /api of the component REST API Endpoint. T…

Patch available
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.3
CVE-2026-76785

A security flaw has been discovered in amirsanni Mini-Inventory-and-Sales-Management-System 0.1. Affected is the function Transaction::getAll of the …

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.3
CVE-2026-76783

A security vulnerability has been detected in DeDeCMS 53_1_UTF8. This vulnerability affects unknown code of the file /plus/advancedsearch.php. Such m…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.1
CVE-2026-8619

An unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.3
CVE-2026-76764

A flaw has been found in code-projects Employee Management System 1.0. The impacted element is an unknown function of the file /process/aprocess.php …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.3
CVE-2026-76762

A vulnerability was detected in code-projects Assessment Management 1.0. The affected element is an unknown function of the file /welcome.php. The ma…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2022-4996

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can lead to floating point compari…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-76928

X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-76924

Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-76923

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-76922

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-76921

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-76919

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-76918

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.5
CVE-2026-76917

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 8.1
CVE-2026-76886

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-76880

RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-76879

C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

No fix yet
Fix from $4,900 2026-08-19