Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.8
CVE-2026-43961

A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context d…

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-16019

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2024-58376

Renovate versions 37.158.0 before 37.199.0 contain a command injection vulnerability in the helmv3 manager's registryAliases handling that allows att…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2020-37267

Renovate versions >=19.180.0 and <23.25.1, when used with Azure DevOps, may expose the bot's authorization token in server or pipeline logs because t…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2019-25766

Renovate versions >= 13.87.0 and <= 19.38.6 leak temporary repository tokens into pull request comments during certain Go Modules update failure scen…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-76235

A memory leak flaw was found in cockpit-ws. The login page handler leaks a heap allocation on every unauthenticated request that carries a CockpitLan…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-73394

Unauthenticated Broken Access Control in Stitch Express <= 1.9.0 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73391

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73390

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73389

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73388

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 8.1
CVE-2026-73387

Unauthenticated Local File Inclusion in Resido <= 1.5 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-73386

Unauthenticated Sensitive Data Exposure in Track Geolocation Of Users Using Contact Form 7 <= 3.0.2 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-73385

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-73384

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73364

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-73363

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.1
CVE-2026-73354

Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73347

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.1
CVE-2026-73184

Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.1
CVE-2026-73182

Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.7
CVE-2026-67363

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept t…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.5
CVE-2026-66668

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-66613

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.1
CVE-2026-66596

Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.1
CVE-2026-61986

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.5
CVE-2026-32552

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

No fix yet
Fix from $4,900 2026-08-19