Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-63231

A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-f…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-63230

A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, …

No fix yet
Fix from $2,300 2026-07-29
Unclassified CRITICAL 9.1
CVE-2026-63229

A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO …

Mitigation only
Fix from $2,300 2026-07-29
Unclassified HIGH 8.1
CVE-2026-14300

The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by i…

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.1
CVE-2026-14234

The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker…

No fix yet
Fix from $1,950 2026-07-29
Unclassified CRITICAL 9.9
CVE-2026-63227

An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP we…

No fix yet
Fix from $2,300 2026-07-29
Unclassified MEDIUM 5.4
CVE-2026-14224

The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-13692

The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 7.4
CVE-2026-13690

The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attac…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.8
CVE-2026-13605

The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into th…

No fix yet
Fix from $1,600 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-13423

The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which …

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 8.6
CVE-2026-11974

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two A…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 5.3
CVE-2026-11351

The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenti…

No fix yet
Fix from $1,600 2026-07-29
Unclassified CRITICAL 9.8
CVE-2026-18072

The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a H…

No fix yet
Fix from $2,300 2026-07-29
Unclassified HIGH 7.2
CVE-2026-12476

The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic…

No fix yet
Fix from $1,950 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-17162

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' B…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-17161

The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-15735

The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-12939

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletter…

No fix yet
Fix from $1,600 2026-07-29
Unclassified MEDIUM 6.4
CVE-2026-12938

The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode…

No fix yet
Fix from $1,600 2026-07-29
Unclassified HIGH 8.8
CVE-2026-12144

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to …

No fix yet
Fix from $1,950 2026-07-29
Unclassified HIGH 7.5
CVE-2026-47219

find-my-way is a framework-independent HTTP router that internally uses a Radix Tree and supports route parameters and wildcards. Versions prior to 9…

No fix yet
Fix from $1,950 2026-07-28
Unclassified CRITICAL 9.4
CVE-2026-6881

A SQL Injection in the Giving Reports functionality in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive …

Mitigation only
Fix from $2,300 2026-07-28
Unclassified MEDIUM 5.3
CVE-2026-16581

In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauth…

No fix yet
Fix from $1,600 2026-07-28
Unclassified HIGH 7.3
CVE-2026-14893

IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.320 IBM Instana Node.js tracer component @instana/core version 6.2.1 is vulnerable t…

No fix yet
Fix from $1,950 2026-07-28
Cloud Pak System HIGH 7.5
CVE-2026-13463

IBM Cloud Pak System 2.3.5.0 could allow a local attacker to obtain sensitive information due to the insertion of credentials into log files.

No fix yet
Fix from $1,950 2026-07-28
Unclassified HIGH 8.1
CVE-2026-48060

Litestar is an Asynchronous Server Gateway Interface (ASGI) framework. Prior to version 2.20.0, Litestar instances which use a template engine in con…

Mitigation only
Fix from $1,950 2026-07-28
Unclassified HIGH 8.8
CVE-2026-16347

MikroTik RouterOS contains a weakness in its API authentication handling that lacks effective safeguards against excessive login attempts. The system…

No fix yet
Fix from $1,950 2026-07-28
Unclassified MEDIUM 5.9
CVE-2026-16107

IBM TS4500 CLI tool Versions:  0.1.31 through 1.12.0.0 does not validate or improperly validates TLS certificate validation, which could allow an att…

No fix yet
Fix from $1,600 2026-07-28
Unclassified MEDIUM 6.3
CVE-2026-11391

Tanium addressed a SQL injection vulnerability in Patch.

No fix yet
Fix from $1,600 2026-07-28