Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-71954

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71953

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71952

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71951

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71950

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71949

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71948

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71947

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71946

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71945

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71944

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified HIGH 7.7
CVE-2026-67620

Flowise through 3.1.4 contains a server-side request forgery vulnerability in the SSRF guard implemented in httpSecurity.ts, where the DEFAULT_DENY_L…

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 7.8
CVE-2026-42170

A heap-based buffer overflow vulnerability exists in the GIMP DDS (DirectDraw Surface) file parser. When a crafted DDS file declares a D3D9 pixel for…

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19288

A vulnerability has been found in astralisone rive-mcp-server-core up to db1d0cc4cd52589116360428b7504fd0ca748b3e. This affects an unknown part of th…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19287

A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by this issue is some unknown functionality of the component HistoryService. This m…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19285

A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778837b9f6399080956eee670d00452c. Affected by this vulnerability is the function J…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19284

A security vulnerability has been detected in MauricioMilano coder-api up to 1.1.0. Affected is the function createProject of the file src/core/proje…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19282

A weakness has been identified in andreahaku llm_memory_mcp up to f11dc8bcff3ff8cf943a2945f99ff3b0bdc8a6d0. This impacts the function auto.capture of…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19281

A security flaw has been discovered in adolfosalasgomez3011 slidev-builder-mcp 2.1.0. This affects the function generateChart of the file src/tools/g…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19279

A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The impacted element is the function load_pdf of the file src/index.ts. Such manipul…

No fix yet
Fix from $1,600 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-68082

In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cl…

No fix yet
Fix from $2,300 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19270

A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2.0. Affected is the function get_journey/delete_journey/analyze_journey/usage_s…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.3
CVE-2026-19268

A vulnerability was identified in abdullah1854 MCPGateway up to 549f494a9e363f40530149de324b8097de424230. This impacts the function getUsageByDateRan…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.0
CVE-2026-16955

The AI Engine WordPress plugin before 3.6.6 does not confine a caller-supplied file path before reading it and forwarding the contents to an externa…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.1
CVE-2026-16948

The Solace Extra WordPress plugin before 1.6.1 does not perform capability checks in several of its AJAX actions and exposes the nonce that protects …

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-16608

The Download Monitor WordPress plugin before 5.2.6 does not perform authorization checks on one of its download-logging AJAX actions, and exposes the…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-16595

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing …

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 7.3
CVE-2026-19263

A vulnerability was found in INQUIRELAB mcp-bridge-api up to b30a82aa1d1d1139e0de846c41c8aadee6e06114. The impacted element is an unknown function of…

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-19259

A vulnerability has been found in MZ Automation libiec61850 up to 1.6.1. The affected element is the function MmsMapping_varAccessSpecToObjectReferen…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 7.7
CVE-2026-16589

The WP Directory Kit WordPress plugin before 1.5.5 does not sanitize and escape a parameter before using it in a SQL statement through one of its aut…

No fix yet
Fix from $1,950 2026-08-08