Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.8
CVE-2026-16069

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX action…

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.3
CVE-2026-15958

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions …

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-14939

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing u…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-14872

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before usin…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14848

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14816

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.8
CVE-2026-10526

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoin…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.7
CVE-2026-16881

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-42169

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR`…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18723

A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18722

A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.2
CVE-2026-14818

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 …

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-8508

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow …

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.2
CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-18720

A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of t…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18719

A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a man…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.2
CVE-2026-58045

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-58042

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-58041

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepa…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-56846

A flaw in Node.js HTTP/2 handling can cause HTTP/2 retained header blocks evade maxSessionMemory and enable remote memory exhaustion. This vulnera…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.5
CVE-2026-56845

An unauthenticated path traversal (LFI) vulnerability exists under /custom-sounds/ when CustomSounds storage is configured to FileSystem. By includin…

No fix yet
Fix from $1,950 2026-08-04
365 Apps HIGH 8.8
CVE-2026-62870

Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-18686

A vulnerability was detected in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function nas-web.add_user of the file /cgi-bin/glc of the …

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-18685

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function set_upgrade of the file /cgi-bin/glc of the com…

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 5.6
CVE-2026-11835

Time-of-check time-of-use (TOCTOU) vulnerability combined with missing input validation in Caliptra Core ROM (UpdateResetFlow::run()) in subsystem mo…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.5
CVE-2026-67978

An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers to cause a Denial of Service (DoS) via transmitting a crafted SBN frame.

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18684

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. This issue affects the function remove_profile of the file /cgi-bin/glc of the compo…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.6
CVE-2026-18667

A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an operator to connect the sens…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67975

Incorrect access control in NASA cFS v7.0.1 allows attackers to arbitrarily remove low-index subscriptions and add new streams via sending TO_LAB add…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-67974

A parser boundary flaw in the Software Bus Network (SBN) application's peer subscription message handling in NASA cFS v7.0.1 allows attackers to caus…

No fix yet
Fix from $1,950 2026-08-03