Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.2
CVE-2026-12476

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-17162

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' B…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-17161

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-15735

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-12939

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletter…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-12938

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.8
CVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-47219

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive …

Mitigation only
Fix from $2,300 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-16581

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauth…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.3
CVE-2026-14893

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable t…

No fix yet
Fix from $1,950 2026-07-28
Cloud Pak System HIGH 7.5
CVE-2026-13463

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.1
CVE-2026-48060

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in con…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.9
CVE-2026-16107

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.3
CVE-2026-11391

Tanium addressed a SQL injection vulnerability in Patch.

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.5
CVE-2026-66745

Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability that allows unauthenticated at…

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 7.7
CVE-2026-50738

A use-after-free condition exists in pglogical's worker signaling code, where a worker structure can be dereferenced after the underlying slot has be…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.0
CVE-2026-50737

When applying replicated changes for a row that is missing one or more columns, pglogical evaluates the affected table's default expressions on the s…

No fix yet
Fix from $2,300 2026-07-28
Unclassified CRITICAL 9.0
CVE-2026-50736

The pglogical queue mechanism, used to convey out-of-band commands such as replicated DDL from a publisher to a subscriber, executes message payloads…

No fix yet
Fix from $2,300 2026-07-28
Unclassified MEDIUM 6.1
CVE-2026-50735

pglogical's apply worker does not sufficiently validate the length of certain fields in incoming replication protocol messages before copying them, r…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 5.5
CVE-2026-47768

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.2, newly-minted operator API key expos…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.9
CVE-2026-47725

nebula-mesh is a self-hosted control plane for Slack Nebula mesh virtual private network. Prior to version 0.3.3, every /ui/* POST / PUT / PATCH / DE…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.8
CVE-2026-16771

In firmware versions 2.7.7 and earlier, the Arris BGW210‑700 gateway fails to enforce any server‑side authentication on its /cgi-bin/*.ha management …

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 10.0
CVE-2026-16498

The terraform-mcp-server before version 1.1.0 is vulnerable to a cross-tenant credential reuse issue in the streamable-HTTP stateless transport mode …

No fix yet
Fix from $2,300 2026-07-28
Unclassified HIGH 8.9
CVE-2026-16496

The terraform-mcp-server before version 1.1.0 is vulnerable to an authorization bypass in the streamable-HTTP stateful transport mode that may allow …

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-15992

The WP Password Policy plugin for WordPress is vulnerable to Privilege Escalation in all versions up to and including 3.7.1. This is due to missing a…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 6.5
CVE-2026-15304

The Plugin Organizer plugin for WordPress is vulnerable to SQL Injection via the 'PO_plugin_path' parameter in versions up to, and including, 10.2.4.…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 8.6
CVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTTP transport that may allow an…

No fix yet
Fix from $1,950 2026-07-28
Photoshop Installer HIGH 8.6
CVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in t…

No fix yet
Fix from $1,950 2026-07-28