Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.8
CVE-2026-14605

A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/l…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 7.3
CVE-2026-58379

A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitra…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.3
CVE-2026-14604

A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file c…

No fix yet
Fix from $1,600 2026-07-03
Unclassified HIGH 8.8
CVE-2026-14460

Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 8.8
CVE-2026-14459

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Ins…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 7.4
CVE-2026-13341

A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 8.5
CVE-2026-10055

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 8.8
CVE-2026-10054

In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.1
CVE-2026-4322

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertisi…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-4321

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertisi…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-9756

The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-4804

The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is …

Mitigation only
Fix from $1,600 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47896

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-35159

Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 5.4
CVE-2026-11778

The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in a…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-11398

The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to,…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.7
CVE-2026-8804

Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-8351

The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in version…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified HIGH 7.2
CVE-2026-9148

The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, …

Mitigation only
Fix from $1,950 2026-07-03
Lucene.net CRITICAL 9.8
CVE-2026-47898

Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap…

Mitigation only
Fix from $2,300 2026-07-03
Lucene.net HIGH 7.5
CVE-2026-47897

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified CRITICAL 9.8
CVE-2026-14544

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attac…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified HIGH 7.5
CVE-2026-4967

In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional executio…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-9626

The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in v…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified CRITICAL 9.1
CVE-2026-9725

The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-9180

The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and i…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-8892

The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Addre…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-8489

The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-12557

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due t…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified HIGH 7.5
CVE-2026-14352

The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter …

Mitigation only
Fix from $1,950 2026-07-03