Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-78050 A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&sec… No fix yet Fix from $5,7502026-08-23 MEDIUM 6.5 CVE-2026-18027 The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerable to Directory Traversal in … No fix yet Fix from $4,0002026-08-23 HIGH 8.8 CVE-2026-16149 The Security Hardener plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 2.4.4. The vulnerability exis… No fix yet Fix from $4,9002026-08-23 HIGH 8.8 CVE-2026-0551 The PPWP – Password Protect Pages plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.9.18 via deseria… No fix yet Fix from $4,9002026-08-23 HIGH 7.4 CVE-2026-78122 docker-socket-proxy fails to properly gate read endpoints in the /containers Docker API namespace when the CONTAINERS environment variable is set. At… Patch available Fix from $4,9002026-08-22 HIGH 7.5 CVE-2026-47895 In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not corre… No fix yet Fix from $4,9002026-08-22 MEDIUM 5.3 CVE-2026-12999 The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a net_buf from the fixed airoc_… Patch available Fix from $4,0002026-08-22 CRITICAL 9.8 CVE-2026-4703 The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, … No fix yet Fix from $5,7502026-08-22 CRITICAL 9.5 CVE-2026-77992 Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform an… No fix yet Fix from $5,7502026-08-22 HIGH 8.6 CVE-2026-77027 Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads t… No fix yet Fix from $4,9002026-08-22 MEDIUM 6.9 CVE-2026-76609 Joomla Extension - fabrikar.com - Unauthenticated modification of any comment in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform any ac… No fix yet Fix from $4,0002026-08-22 MEDIUM 6.9 CVE-2026-76608 Joomla Extension - fabrikar.com - Unauthenticated disclosure of any commenter's email address in Fabrik < 4.7.2 - The onGetEmail endpoint did not per… No fix yet Fix from $4,0002026-08-22 CRITICAL 10.0 CVE-2026-76607 Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2. No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76606 Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2. No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76605 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2. No fix yet Fix from $5,7502026-08-22 CRITICAL 10.0 CVE-2026-76604 Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable t… No fix yet Fix from $5,7502026-08-22 MEDIUM 6.9 CVE-2026-76603 Joomla Extension - fabrikar.com - Unauthenticated row disclosure via form.inlineedit in Fabrik < 4.7.2 - The inineedit form controller does not perfo… No fix yet Fix from $4,0002026-08-22 CRITICAL 9.3 CVE-2026-76602 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries… No fix yet Fix from $5,7502026-08-22 MEDIUM 6.9 CVE-2026-76601 Joomla Extension - fabrikar.com - Unauthenticated row reordering in Fabrik < 4.7.2 - The order plugin did not perform any access checks. No fix yet Fix from $4,0002026-08-22 MEDIUM 6.9 CVE-2026-76600 Joomla Extension - fabrikar.com - Unauthenticated deletion of any comment in Fabrik < 4.7.2 - The DeleteComment endpoint did not perform any access c… No fix yet Fix from $4,0002026-08-22 HIGH 8.7 CVE-2026-76599 Joomla Extension - fabrikar.com - Unauthenticated database table list and table-prefix disclosure in Fabrik < 4.7.2 - The ajax_tables method of the e… No fix yet Fix from $4,9002026-08-22 HIGH 8.7 CVE-2026-76598 Joomla Extension - fabrikar.com - Unauthenticated arbitrary directory listing via onAjax_getFolders in Fabrik < 4.7.2 - The onAjax_getFolders method … No fix yet Fix from $4,9002026-08-22 HIGH 8.7 CVE-2026-76597 Joomla Extension - fabrikar.com - Unauthenticated arbitrary file upload to web root via list email plugin in Fabrik < 4.7.2 - The list email plugin c… No fix yet Fix from $4,9002026-08-22 HIGH 8.7 CVE-2026-76596 Joomla Extension - fabrikar.com - Unauthenticated table truncation via list.doempty in Fabrik < 4.7.2- The list controllers doemtpy endpoints lacks A… No fix yet Fix from $4,9002026-08-22 CRITICAL 9.3 CVE-2026-76571 Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed… No fix yet Fix from $5,7502026-08-22 MEDIUM 6.2 CVE-2026-70626 NLTK versions before 3.9.4 contain a symlink escape vulnerability in CorpusReader.open() that allows local attackers to read arbitrary files outside … No fix yet Fix from $4,0002026-08-22 MEDIUM 6.1 CVE-2026-68768 hashcat contains a heap-based buffer overflow (out-of-bounds write) in the outfile_write() function in src/outfile.c. When assembling output into a f… Patch available Fix from $4,0002026-08-22 MEDIUM 6.1 CVE-2026-68767 hashcat's fgetl() function in src/filehandling.c writes a null terminator one byte past the caller's buffer when an input line is exactly the buffer … Patch available Fix from $4,0002026-08-22 HIGH 7.8 CVE-2026-68766 hashcat fails to restrict command-line options when parsing restore files, allowing attackers to inject output-redirecting options like --outfile and… Patch available Fix from $4,9002026-08-22 HIGH 7.5 CVE-2026-66393 NLTK versions before 3.9.4 contain an unbounded recursion vulnerability in JSONTaggedDecoder.decode_obj() that allows attackers to cause denial of se… No fix yet Fix from $4,9002026-08-22