Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-16461

A stack-based buffer overflow was found in rpcbind's rpcinfo utility. In rpcbdump() short mode (used by `rpcinfo -s`), version numbers from a remote …

No fix yet
Fix from $1,600 2026-07-21
Unclassified CRITICAL 9.1
CVE-2026-62415

Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2…

No fix yet
Fix from $2,300 2026-07-21
Unclassified HIGH 7.2
CVE-2026-1771

The MapSVG plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the SVGFile constructor in all version…

No fix yet
Fix from $1,950 2026-07-21
Hardened Images HIGH 7.3
CVE-2026-15370

A flaw was found in libssh. During SFTP server directory listing, the longname field is constructed with unsafe concatenation into a fixed-size stack…

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 5.3
CVE-2026-8593

Improper permission enforcement in Checkmk versions 2.5.0 before 2.5.0p9, 2.4.0 before 2.4.0p34, 2.3.0 before 2.3.0p49, and 2.2.0 (EOL) allows users …

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.1
CVE-2026-3183

Zohocorp ManageEngine ADSelfService Plus versions before 6524 are vulnerable to Multi Factor Authentication Bypass.

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.5
CVE-2026-8082

The bpost-shipping-platform WordPress plugin before 3.2.3 does not properly sanitize a parameter before using it in a SQL query during WooCommerce or…

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 5.4
CVE-2026-14184

The Academy LMS WordPress plugin before 3.8.1 does not verify ownership of a user-supplied user identifier in several of its lesson AJAX handlers, al…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.5
CVE-2026-13694

The Bit Form WordPress plugin before 3.1.0 does not properly validate its workflow-trigger token once the associated transient has expired, allowing…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.9
CVE-2026-13693

The Bit Form WordPress plugin before 3.1.0 does not restrict a form file-field value to a safe path before reading the file and attaching it to a no…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 8.8
CVE-2026-11767

The Free Builder for Elementor WordPress plugin before 1.6.7 does not sanitise submitted contact form field values before storing them and outputti…

Mitigation only
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.8
CVE-2026-15927

A flaw was found in Red Hat Quay's repository-level mirror configuration feature. The POST and PUT handlers in endpoints/api/mirror.py accept an exte…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 5.8
CVE-2026-15811

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not correctly zero-out or wipe s…

No fix yet
Fix from $1,600 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-13439

The Easy Form Builder by WhiteStudio plugin for WordPress is vulnerable to Unauthenticated Privilege Escalation to Administrator in versions up to, a…

No fix yet
Fix from $2,300 2026-07-21
Unclassified MEDIUM 6.4
CVE-2026-15156

The Essential Addons for Elementor – Popular Elementor Templates & Widgets plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Read…

No fix yet
Fix from $1,600 2026-07-21
Unclassified MEDIUM 6.8
CVE-2026-59776

Missing Cryptographic Step (CWE-325) vulnerability exists in certain FeliCa IC chips shipped in or before 2017. If the vulnerability is exploited, in…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.2
CVE-2026-6952

A post-authentication command injection vulnerability in the "LogServer" field of the syslog component in Zyxel AX7501-B1 firmware versions through 5…

No fix yet
Fix from $1,950 2026-07-21
Unclassified MEDIUM 6.3
CVE-2026-16334

A vulnerability was identified in itsourcecode Hospital Management System 1.0. This vulnerability affects unknown code of the file /prescriptionorder…

No fix yet
Fix from $1,600 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16332

A vulnerability was detected in D-Link DNS-320 1.0.2. This impacts an unknown function of the file /mydlink/multi_uploadify.php. Performing a manipul…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16331

A security vulnerability has been detected in D-Link DNS-320 1.0.2. This affects an unknown function of the file /web/function/save_ajax.php. Such ma…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16330

A weakness has been identified in D-Link DNS-320 1.0.2. The impacted element is an unknown function of the file /web/jquery/uploader/uploadify.php. T…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16329

A vulnerability was identified in D-Link DNS-320 1.0.2. Impacted is an unknown function of the file /photo_center/php/uploadify.php. The manipulation…

No fix yet
Fix from $1,950 2026-07-21
Unclassified HIGH 7.3
CVE-2026-16327

A vulnerability was determined in D-Link DNS-320 1.0.2. This issue affects some unknown processing of the file /web/web_file/upload.php. Executing a …

No fix yet
Fix from $1,950 2026-07-21
Unclassified CRITICAL 9.8
CVE-2026-64625

AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command…

No fix yet
Fix from $2,300 2026-07-20
Unclassified MEDIUM 5.6
CVE-2026-57852

Grav CMS scheduler-webhook plugin contains an authentication bypass vulnerability that allows unauthenticated remote attackers to trigger configured …

No fix yet
Fix from $1,600 2026-07-20
Unclassified HIGH 8.2
CVE-2026-57495

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/claudecode prior to version 0.2.39, @agenticmail/codex prior to v…

Mitigation only
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-57494

AgenticMail gives AI agents real email addresses and phone numbers. In @agenticmail/api prior to version 0.9.64, a low-privileged authenticated Agent…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.1
CVE-2026-55550

NextCRM is open-source customer relationship management (CRM) software. The CRM product catalog is an organization-wide business object. Normal appli…

No fix yet
Fix from $1,950 2026-07-20
Unclassified HIGH 7.6
CVE-2026-55544

NextCRM is open-source customer relationship management (CRM) software. In version 0.12.1, the MCP campaign tools expose campaign read and write oper…

No fix yet
Fix from $1,950 2026-07-20
Unclassified CRITICAL 9.8
CVE-2026-52656

An issue in SJCAM AllWinner Tech products SJ4000-Air V1.4C and before and Whitelabel based v.1.4C and before allows an attacker to execute arbitrary …

No fix yet
Fix from $2,300 2026-07-20