Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 10.0
CVE-2026-33591

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially …

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.3
CVE-2026-0392

eParakstītājs 3.0 for Windows before version 1.10.0 retrieves and executes its automatic updates over a channel that is not authenticated or integrit…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-63563

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication feature disabled in the initi…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-62416

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, require no authentication and accep…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-60011

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image data stored to the affected …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-8794

PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnera…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.9
CVE-2026-8793

PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploi…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-28147

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorr…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21555

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21554

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21553

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21552

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21551

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21550

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21549

In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 7.5
CVE-2026-21548

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed.

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.6
CVE-2026-18593

A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmp…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.3
CVE-2026-18590

A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-12259

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them bef…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.7
CVE-2026-9593

A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a …

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18589

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of th…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18588

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the arg…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 7.5
CVE-2026-18587

A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a m…

No fix yet
Fix from $1,950 2026-08-03
Unclassified HIGH 8.6
CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthen…

No fix yet
Fix from $1,950 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-16563

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through i…

No fix yet
Fix from $1,600 2026-08-03
Unclassified HIGH 8.1
CVE-2026-16539

The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating…

No fix yet
Fix from $1,950 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-16534

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-16532

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16300

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi…

No fix yet
Fix from $2,300 2026-08-03