Vulnerability index

Browse CVEs

1,930 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Enterprise Linux HIGH 7.5
CVE-2026-73197

A flaw was found in FreeIPA. A remote, unauthenticated attacker can exploit this vulnerability by sending oversized form POST requests to the `/ipa/m…

Fix: 4.13.3+
Fix from $4,900 2026-08-20
Enterprise Linux CRITICAL 9.1
CVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se…

No fix yet
Fix from $5,750 2026-08-20
Enterprise Linux HIGH 8.1
CVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti…

Fix: 4.13.3+
Fix from $4,900 2026-08-20
Unclassified HIGH 7.8
CVE-2026-18917

A flaw was found in libvirt. An unprivileged local user could exploit an integer overflow vulnerability in the NodeGetFreePages RPC handler. This fla…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-77014

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-headers.c truncates a 64-bit subt…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.9
CVE-2026-76610

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint lacked ACL checks, allowing una…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-14952

An unauthenticated remote attacker can retrieve sensible files from the FDS Web server, such as the backup archive at /FdsBackup.zip and additional f…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.0
CVE-2026-14951

An low privileged remote attacker can cause authenticated users to perform unintended actions in the FDS Web interface using malicious web pages.

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-14950

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.5
CVE-2026-14949

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed through /api/user/add.php to cr…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.8
CVE-2026-14948

A low privileged remote attacker can hijack an active administrative session without needing to know the administrator password by extracting live pl…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.2
CVE-2026-14947

A high-privileged remote attacker can upload malicious ZIP archive containing directory traversal sequences such as ../ can escape the intended extra…

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 7.2
CVE-2026-14946

A high privileged remote attacker can upload a .php file and then request it directly from /uploads/<filename>.php to achieve arbitrary code executio…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-76569

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-76565

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 8.6
CVE-2026-76564

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.6
CVE-2026-75948

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event" form stores the `image` and …

No fix yet
Fix from $4,900 2026-08-20
Unclassified HIGH 8.6
CVE-2025-14601

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execute arbitrary operating system…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.1
CVE-2026-71368

F-RevoCRM contains a cross-site scripting vulnerability. If a user views a crafted page while logged in to the affected product, unintended operation…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.1
CVE-2026-14163

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the deployment variable sn…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 5.3
CVE-2025-14602

The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a remote attacker to ac…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.5
CVE-2026-75963

The Events Made Easy plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 3.2.5 via the eme_single_event_…

No fix yet
Fix from $4,900 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-75860

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r…

No fix yet
Fix from $5,750 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-74992

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users with the Editor role, and does …

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-19697

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables, allowing users with the file …

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 6.8
CVE-2026-19615

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route it accepts them through, allo…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.3
CVE-2026-17153

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.7. This is due to the…

No fix yet
Fix from $4,000 2026-08-20
Unclassified HIGH 7.2
CVE-2026-15049

The Depicter — Popup & Slider Builder WordPress plugin before 4.8.0 does not validate the type of a file uploaded through its import feature and does…

No fix yet
Fix from $4,900 2026-08-20
Unclassified MEDIUM 6.6
CVE-2026-13405

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not correctly sanitise custom widget markup before writing it to a file that is…

No fix yet
Fix from $4,000 2026-08-20
Unclassified MEDIUM 5.9
CVE-2026-76956

In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentropy's return code leads to insufficient entropy, which results in being vulnera…

Patch available
Fix from $4,000 2026-08-20