Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.4
CVE-2026-16574

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.11 does not verify that a downloadable product belong…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.8
CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload features and permits their upload b…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 7.5
CVE-2026-16594

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing …

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-16590

The WP Directory Kit WordPress plugin before 1.5.5 does not perform authorization or nonce checks on one of its authenticated AJAX actions, allowing …

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 7.5
CVE-2026-16578

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability che…

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-16562

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only o…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and do…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.1
CVE-2026-16535

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthentic…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-16282

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured ser…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.1
CVE-2026-16267

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, al…

No fix yet
Fix from $1,950 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-14526

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du…

No fix yet
Fix from $2,300 2026-08-08
Unclassified MEDIUM 6.4
CVE-2026-18988

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, a…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.7
CVE-2026-13505

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material …

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 8.7
CVE-2026-8798

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions …

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 7.5
CVE-2026-52880

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-52879

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-52878

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.9
CVE-2026-49343

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-48122

Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to v…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.7
CVE-2026-48026

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.8…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-47249

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.6
CVE-2026-46409

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…

No fix yet
Fix from $2,300 2026-08-07
Unclassified MEDIUM 5.7
CVE-2026-64676

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the …

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.8
CVE-2026-48169

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-47243

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

No fix yet
Fix from $2,300 2026-08-07
Unclassified MEDIUM 6.8
CVE-2026-9031

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.8
CVE-2026-9030

A denial-of-service vulnerability exists in httpd service on Archer A6 v4 where the asynchronous systool instruction handlng path in httpd does not p…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.6
CVE-2026-47664

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47663

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 8.7
CVE-2026-47662

Pathling is a set of tools that make it easier to use FHIR and clinical terminology within health data analytics. Prior to version 2.0.0 of Pathling …

No fix yet
Fix from $1,950 2026-08-07