Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.4
CVE-2026-15285

The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.4
CVE-2026-15284

The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, a…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 7.5
CVE-2026-15288

The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and i…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 9.8
CVE-2026-15282

The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-5069

The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.2
CVE-2026-54423

In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_r…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.5
CVE-2026-44918

OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-11818

The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.8
CVE-2026-15070

The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 7.2
CVE-2026-13430

The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the im…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 6.1
CVE-2026-11392

The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in …

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-15320

A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pi…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15318

A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqt…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified MEDIUM 6.3
CVE-2026-15317

A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file p…

Mitigation only
Fix from $1,600 2026-07-10
Unclassified HIGH 8.1
CVE-2026-54771

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat inter…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified CRITICAL 10.0
CVE-2026-54769

Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape …

Mitigation only
Fix from $2,300 2026-07-10
Unclassified CRITICAL 9.3
CVE-2026-54760

Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation,…

Mitigation only
Fix from $2,300 2026-07-10
Unclassified HIGH 8.1
CVE-2026-12598

The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login add…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-12597

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3.…

Mitigation only
Fix from $1,950 2026-07-10
Unclassified HIGH 8.1
CVE-2026-12595

The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. …

Mitigation only
Fix from $1,950 2026-07-10
Unclassified MEDIUM 5.4
CVE-2026-58144

Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbit…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 8.8
CVE-2026-58143

Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator co…

Mitigation only
Fix from $1,950 2026-07-09
Junos MEDIUM 5.9
CVE-2026-57030

A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of …

Mitigation only
Fix from $1,600 2026-07-09
Junos Os Evolved MEDIUM 5.3
CVE-2026-57029

A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthen…

Mitigation only
Fix from $1,600 2026-07-09
Junos MEDIUM 5.3
CVE-2026-57021

An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-b…

Mitigation only
Fix from $1,600 2026-07-09
Junos HIGH 7.5
CVE-2026-57023

An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and …

Mitigation only
Fix from $1,950 2026-07-09
Unclassified MEDIUM 5.3
CVE-2026-55605

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ariku…

Mitigation only
Fix from $1,600 2026-07-09
Unclassified HIGH 8.6
CVE-2026-55604

DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts…

Mitigation only
Fix from $1,950 2026-07-09
Unclassified HIGH 7.5
CVE-2026-38076

An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a cra…

Mitigation only
Fix from $1,950 2026-07-09
Junos MEDIUM 5.5
CVE-2026-33802

A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-o…

Mitigation only
Fix from $1,600 2026-07-09