Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 8.8
CVE-2026-13352

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vul…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.3
CVE-2026-8616

The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing n…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.2
CVE-2026-15395

The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'digitalSignature' Field …

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.1
CVE-2026-11324

The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'red…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 7.1
CVE-2026-62387

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 shipped Access-Control-Allow-Origin: * as its default CORS configuration on all resp…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-62386

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.0-rc.16 accepts JWT access tokens through the ?token= URL query parameter on every API route…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 6.5
CVE-2026-62237

Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlist…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 5.4
CVE-2026-62236

grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which rege…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.3
CVE-2026-62235

Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with…

No fix yet
Fix from $1,600 2026-07-17
Unclassified HIGH 8.1
CVE-2026-62234

Grav before 2.0.4 fails to restrict cURL protocols in webhook dispatch, allowing authenticated users with api.webhooks.write permission to create web…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 8.8
CVE-2026-62233

grav-plugin-api before 1.0.6 fails to validate super-admin status in createApiKey, generate2fa, and disable2fa endpoints, allowing non-super api.user…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 7.4
CVE-2026-62232

Grav before 2.0.4 contains a two-factor authentication bypass vulnerability in the login plugin where the regenerate2FASecret task checks only user e…

No fix yet
Fix from $1,950 2026-07-17
Unclassified HIGH 8.1
CVE-2026-62231

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.6 contains an authorization bypass: API keys can be created with a restricted scopes array, …

Mitigation only
Fix from $1,950 2026-07-17
Unclassified HIGH 7.5
CVE-2026-62230

Grav before 2.0.4 ships a default .htaccess (and reference webserver-configs/htaccess.txt) whose rules blocking access to sensitive file types (.yaml…

No fix yet
Fix from $1,950 2026-07-17
Unclassified MEDIUM 5.4
CVE-2026-62224

OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attacker…

No fix yet
Fix from $1,600 2026-07-17
Unclassified MEDIUM 6.4
CVE-2026-2594

The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to ins…

No fix yet
Fix from $1,600 2026-07-17
Unclassified CRITICAL 9.8
CVE-2026-14956

The Bricksforge plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.1.8.6. This is due to improper val…

No fix yet
Fix from $2,300 2026-07-17
Unclassified HIGH 8.1
CVE-2026-43978

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged …

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 7.5
CVE-2026-43977

wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout ses…

No fix yet
Fix from $1,950 2026-07-16
Terminal HIGH 7.5
CVE-2026-59117

Integer overflow or wraparound in Windows Terminal allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.4
CVE-2026-45368

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the underlying URL methods for the KirbyTags and image block…

Mitigation only
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.3
CVE-2026-45334

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, the content-locking feature returned lock information withou…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.8
CVE-2026-44177

Kirby is an open-source content management system. In versions 5.3.0 and above but prior to 5.4.1, Kirby did not correctly validate the provided user…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 6.0
CVE-2026-44176

Kirby is an open-source content management system. Versions prior to 4.9.1 and 5.4.1 do not check the `pages.access` permission during page draft re…

No fix yet
Fix from $1,600 2026-07-16
Unclassified HIGH 8.5
CVE-2026-44175

Kirby is an open-source content management system. In versions prior to 4.9.1 and 5.4.1, Kirby did not securely sanitize the contents of the list fie…

No fix yet
Fix from $1,950 2026-07-16
Unclassified HIGH 8.7
CVE-2026-44174

Kirby is an open-source content management system. Prior to 4.9.1 and 5.4.1, Kirby did not validate the model attributes that were used in its collec…

No fix yet
Fix from $1,950 2026-07-16
Unclassified MEDIUM 5.5
CVE-2026-61378

A divide-by-zero vulnerability in the Productivity Suite allows a local attacker to cause a division by zero leading to a system crash.

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 5.9
CVE-2026-60073

An out-of-bounds read in the Productivity Suite allows a physical attacker to control the length of data sent to a USB device. This can lead to a s…

No fix yet
Fix from $1,600 2026-07-16
Unclassified MEDIUM 6.1
CVE-2026-57896

An out-of-bounds read vulnerability in the Productivity Suite allows a local attacker to trigger kernel memory corruption by sending a crafted IOCT…

No fix yet
Fix from $1,600 2026-07-16
Unclassified CRITICAL 9.8
CVE-2026-38158

A SQL injection vulnerability in the /ureport/datasource/previewData component of ureport v2.2.9 allows attackers to access sensitive database inform…

No fix yet
Fix from $2,300 2026-07-16