Vulnerability index

Browse CVEs

2,061 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.9 CVE-2026-77710 A vulnerability in misp-stix could allow a crafted STIX document to influence security-sensitive MISP attribute metadata during import. The STIX imp… Patch available Fix from $4,0002026-08-21 HIGH 8.1 CVE-2026-68745 Certificate validation failures in SAML authentication in Apache CloudStack 4.20.3.0 and 4.22.1.0 on all platforms allow a malicious agent to forge a… No fix yet Fix from $4,9002026-08-21 HIGH 7.2 CVE-2026-66722 Improper authorization for CRUD operations on Project Roles and Project Role permissions for domain admins in CloudStack. A Domain Admin can crea… No fix yet Fix from $4,9002026-08-21 MEDIUM 5.8 CVE-2026-74866 @fastify/busboy is a multipart form-data parser for Node.js. Its multipart part-header parser splits header lines only on the two-byte carriage-retur… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.4 CVE-2026-66797 Improper access control in CloudStack's annotation functionality allows unauthorized comment creation and disclosure. The addAnnotation and listA… No fix yet Fix from $4,0002026-08-21 HIGH 8.8 CVE-2026-63046 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Apache InLong. Agent Installer's ModuleManager ex… No fix yet Fix from $4,9002026-08-21 CRITICAL 9.1 CVE-2026-62440 Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes cl… Fix unknown Fix from $5,7502026-08-21 CRITICAL 9.1 CVE-2026-61398 Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. This issue affect… Fix unknown Fix from $5,7502026-08-21 HIGH 7.5 CVE-2026-61397 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integra… Fix unknown Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-61400 Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics func… No fix yet Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-59780 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP provide… Fix unknown Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-59657 Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. This issue affects Apache Cloud… Fix unknown Fix from $4,9002026-08-21 HIGH 7.5 CVE-2026-59655 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth provi… Fix unknown Fix from $4,9002026-08-21 CRITICAL 9.1 CVE-2026-59085 Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. This issue affect… Fix unknown Fix from $5,7502026-08-21 HIGH 7.5 CVE-2026-50222 Missing Authorization, Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's Userdata reference APIs. Seve… Fix unknown Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-59799 Improper Privilege Management vulnerability in Apache CloudStack's Two-factor authentication plugin allowing bypass of the two-factor authentication … No fix yet Fix from $4,9002026-08-21 HIGH 8.8 CVE-2026-50112 SSRF via Metalink Mirror URL Resolution: An authenticated tenant can register a template pointing to an attacker-controlled metalink file containing… No fix yet Fix from $4,9002026-08-21 CRITICAL 9.8 CVE-2026-77264 The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypas… No fix yet Fix from $5,7502026-08-21 MEDIUM 5.3 CVE-2026-19441 Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: thr… No fix yet Fix from $4,0002026-08-21 HIGH 7.5 CVE-2026-16323 Execution after redirect (EAR) vulnerability in FuyaWeb Internet and Informatics Services ArchitectPanel Web Admin Panel allows Authentication Bypass… No fix yet Fix from $4,9002026-08-21 HIGH 7.2 CVE-2026-75796 The AI Engine WordPress plugin before 3.6.1 does not verify that the requesting user is authorized to act on the targeted account before performing … No fix yet Fix from $4,9002026-08-21 HIGH 8.1 CVE-2026-18781 The Drag and Drop Multiple File Upload for Contact Form 7 WordPress plugin before 1.3.9.9 does not validate the final name of an uploaded file after … No fix yet Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-16962 The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its public payment cancel/fail ret… No fix yet Fix from $4,0002026-08-21 MEDIUM 6.8 CVE-2026-16959 The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it into a SQL query in one of its … No fix yet Fix from $4,0002026-08-21 HIGH 7.2 CVE-2026-16576 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not correctly check user capabilities on some… No fix yet Fix from $4,9002026-08-21 MEDIUM 5.3 CVE-2026-16575 The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict access to per-vendor commission … No fix yet Fix from $4,0002026-08-21 MEDIUM 6.8 CVE-2026-14601 The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in a SQL query, allowing authen… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.3 CVE-2026-13736 The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on an unauthenticated REST route,… No fix yet Fix from $4,0002026-08-21 MEDIUM 5.4 CVE-2025-15671 The Welcart e-Commerce WordPress plugin before 2.12.1 does not regenerate the session identifier on authentication and sets the session identifier fr… No fix yet Fix from $4,0002026-08-21 HIGH 7.2 CVE-2026-18409 The WPForms Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Single Line Text and Paragraph Text Field Values in all version… No fix yet Fix from $4,9002026-08-21