Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-19489

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.1
CVE-2026-18371

HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to o…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.1
CVE-2026-75900

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(…

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.4
CVE-2026-58088

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over th…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.8
CVE-2026-58087

The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buf…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.4
CVE-2026-58083

While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the …

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.2
CVE-2026-75981

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripti…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-8810

On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.8
CVE-2026-49429

The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but …

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.4
CVE-2026-49428

Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.4
CVE-2026-49422

The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, i…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-49420

The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer,…

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 8.8
CVE-2026-19842

The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, an…

No fix yet
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.4
CVE-2026-19782

The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such a…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-19709

The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing …

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-19417

The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticat…

No fix yet
Fix from $4,000 2026-08-19
Unclassified HIGH 7.1
CVE-2026-19056

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one …

No fix yet
Fix from $4,900 2026-08-19
Unclassified HIGH 7.1
CVE-2026-19055

The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes …

No fix yet
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.0
CVE-2026-18937

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalink…

No fix yet
Fix from $5,750 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-18779

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-18778

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-18777

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to…

No fix yet
Fix from $4,000 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-18776

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t…

No fix yet
Fix from $5,750 2026-08-19
Unclassified MEDIUM 5.4
CVE-2026-18466

The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with…

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.3
CVE-2026-18231

The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered …

No fix yet
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.8
CVE-2026-18202

The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing us…

No fix yet
Fix from $4,000 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-18051

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthentic…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-18031

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated wi…

No fix yet
Fix from $5,750 2026-08-19
Unclassified HIGH 7.2
CVE-2026-17565

The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a serv…

No fix yet
Fix from $4,900 2026-08-19