Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-16298

The FoodBoxBooker WordPress plugin before 1.0.7 does not properly validate the password reset request, allowing unauthenticated attackers to reset th…

No fix yet
Fix from $2,300 2026-08-10
Unclassified MEDIUM 6.1
CVE-2026-17019

The JetEngine WordPress plugin before 3.8.13.1 does not sanitise uploaded SVG files before storing and serving them, and does not adequately restrict…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-17010

The Saitama Addon Pack WordPress plugin through 1.0.8 does not sanitise and escape certain post metadata values before outputting them, allowing user…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-15229

The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side, allowing unauthenticated user…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.2
CVE-2026-16257

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints, whose only access control can b…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-15238

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not verify record ownership before updating customer records, allowing any authenticat…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-15237

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint that creates payme…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 6.8
CVE-2026-15047

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside an inline script context, all…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.4
CVE-2026-14941

The Customer Reviews for WooCommerce WordPress plugin before 5.116.0 does not perform nonce or capability checks on several settings-related AJAX act…

No fix yet
Fix from $1,600 2026-08-10
Unclassified MEDIUM 5.3
CVE-2026-14860

The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 8.8
CVE-2026-14293

The Autopay WordPress plugin before 5.0.1 does not perform any capability or nonce check before saving a styling option from a public request, and do…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.2
CVE-2026-13170

The Eventin WordPress plugin before 4.1.20 does not properly validate a template path setting before using it to include a local file, allowing user…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.2
CVE-2026-14237

The vitepos WordPress plugin before 3.6.0, Vitepos WordPress plugin before 3.5.0 do not perform a per-target authorization check in their point-of-s…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.1
CVE-2026-13600

The AutoNetTV Relay WordPress plugin before 3.0.14 does not perform any capability or authentication check before setting a WordPress administrator a…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.5
CVE-2026-14206

The HT Contact Form WordPress plugin before 2.9.3 does not perform any authorization check on the endpoint that returns a saved form draft, allowing…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 8.4
CVE-2026-13133

A vulnerability has been identified in LineInst.exe (LINE for Windows) prior to version 26.4.0, where Msftedit.dll is loaded via a relative path with…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.1
CVE-2026-19389

Multiple integer overflow and underflow vulnerabilities were found in the GStreamer gst-plugins-ugly ASF demuxer (asfdemux) when parsing header objec…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.6
CVE-2026-19387

A heap out-of-bounds write vulnerability was found in the GStreamer gst-plugins-bad adpcmdec element when decoding IMA/DVI ADPCM audio. Insufficient …

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.3
CVE-2026-19384

A weakness has been identified in SourceCodester Simple Doctors Appointment System 1.0. The affected element is an unknown function of the file /admi…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.8
CVE-2026-19381

A security flaw has been discovered in Kingston FURY CTRL RGB Control Software 2.0.65.0. The impacted element is an unknown function in the library N…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.3
CVE-2026-19379

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the component CGI Endpoint. Th…

No fix yet
Fix from $1,950 2026-08-10
Unclassified HIGH 7.3
CVE-2026-19376

A vulnerability has been found in Uasoft Badaso 3.0.0-alpha. This vulnerability affects the function ApiRequest::class of the file src/Routes/api.php…

No fix yet
Fix from $1,950 2026-08-10
Unclassified MEDIUM 6.3
CVE-2026-19375

A vulnerability was detected in dmitriiweb article-scraper-mcp 1.0.0. This vulnerability affects the function fetch_article of the file news_scraper_…

No fix yet
Fix from $1,600 2026-08-10
Unclassified HIGH 7.3
CVE-2026-19374

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of…

No fix yet
Fix from $1,950 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19373

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function makeRequest of the file src/index…

No fix yet
Fix from $1,600 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19372

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability is the function fs.readFileSy…

No fix yet
Fix from $1,600 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19371

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the file src/tools/utils.ts of the c…

No fix yet
Fix from $1,600 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19370

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSync/fs.readFileSync of the file…

No fix yet
Fix from $1,600 2026-08-09
Unclassified MEDIUM 5.3
CVE-2026-19369

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.ts of the component add_attac…

No fix yet
Fix from $1,600 2026-08-09
Unclassified MEDIUM 6.3
CVE-2026-19367

A vulnerability has been found in NocteDefensor LudusMCP 1.0.24. Affected by this vulnerability is an unknown functionality of the file src/tools/ran…

No fix yet
Fix from $1,600 2026-08-09