Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.9 CVE-2026-59296 Using untrusted, non-normalized input as-is for metrics data (such as metric names, tag keys, or tag values) is a dangerous antipattern that general-… No fix yet Fix from $4,0002026-08-21 MEDIUM 6.9 CVE-2026-15576 Improper authentication in the agent receiver of Checkmk <2.5.0p10 allows an unauthenticated remote attacker to bypass mutual TLS client certificate … No fix yet Fix from $4,0002026-08-21 HIGH 7.3 CVE-2026-14208 Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL files in the installation directory (C:\Program Files (x86)\Remote Utilities - Host\), … No fix yet Fix from $4,9002026-08-21 HIGH 8.7 CVE-2026-77755 A denial-of-service vulnerability was identified in misp-stix when processing attacker-controlled STIX 1 or STIX 2 documents. The STIX import code u… Patch available Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-77751 A path traversal vulnerability existed in the handling of MISP object template names during STIX 2 import and MISP-to-STIX 2 export. MISP object nam… Patch available Fix from $4,9002026-08-21 MEDIUM 6.3 CVE-2026-77681 A vulnerability was identified in CodeAstro Online Job Portal 1.0. Affected by this vulnerability is an unknown functionality of the file /users/upda… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-59323 An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of service (DoS) due to unbounded ob… No fix yet Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-47827 Command Injection in BOSH CLI tool on windows in Cloud Foundry allows a remote attacker to execute arbitrary shell commands via command injection vul… No fix yet Fix from $4,9002026-08-21 MEDIUM 6.9 CVE-2026-77710 A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX imp… Patch available Fix from $4,0002026-08-21 MEDIUM 5.8 CVE-2026-74866 @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-retur… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.4 CVE-2026-66797 Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listA… No fix yet Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-63046 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager ex… No fix yet Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-61400 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics func… No fix yet Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-50112 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing… No fix yet Fix from $4,9002026-08-21 CRITICAL 9.8 CVE-2026-77264 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas… No fix yet Fix from $5,7502026-08-21 MEDIUM 5.3 CVE-2026-19441 Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: thr… No fix yet Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-16323 Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass… No fix yet Fix from $4,9002026-08-21 HIGH 7.2 CVE-2026-75796 The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing … No fix yet Fix from $4,9002026-08-21 HIGH 8.1 CVE-2026-18781 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after … No fix yet Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-16962 The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail ret… No fix yet Fix from $4,0002026-08-21 MEDIUM 6.8 CVE-2026-16959 The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its … No fix yet Fix from $4,0002026-08-21 HIGH 7.2 CVE-2026-16576 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some… No fix yet Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-16575 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission … No fix yet Fix from $4,0002026-08-21 MEDIUM 6.8 CVE-2026-14601 The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authen… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-13736 The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route,… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.4 CVE-2025-15671 The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier fr… No fix yet Fix from $4,0002026-08-21 HIGH 7.2 CVE-2026-18409 The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all version… No fix yet Fix from $4,9002026-08-21 CRITICAL 9.3 CVE-2026-76158 External Control of File Name or Path in the upload API endpoint of Datiphy Data Management Center from v8.3.0 through v8.5.1 allows a remote attacke… No fix yet Fix from $5,7502026-08-21 MEDIUM 5.3 CVE-2026-76131 Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALOID6 Editor and gain access to… No fix yet Fix from $4,0002026-08-21 HIGH 7.7 CVE-2026-73267 A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete Clus… No fix yet Fix from $4,9002026-08-21