Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.2
CVE-2026-13040

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'real_val__' parameter …

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.5
CVE-2026-11397

The WP Import Export Lite plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to and including 3.9.30 via the wpie_i…

No fix yet
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.0
CVE-2026-12960

An Improper Export of Android Application Components vulnerability in ASUS Router App allows a third-party application on the same device to send a c…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified HIGH 8.5
CVE-2026-8921

External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 7.3
CVE-2022-4990

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to bypass securi…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified HIGH 8.5
CVE-2022-4989

** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quantity in Input in the ASUS AI Suite 3 driver allows a local user to access uninte…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-12734

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 6.4
CVE-2026-12731

The weDocs: AI Powered Knowledge Base, Docs, Documentation, Wiki & AI Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via '…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified HIGH 7.5
CVE-2026-14327

The AR for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter pa…

Mitigation only
Fix from $1,950 2026-07-03
Unclassified MEDIUM 5.3
CVE-2026-55726

The Azure Blob Storage container used for Gardyn device logs is publicly listable without authentication. A malicious user would be able to access an…

Mitigation only
Fix from $1,600 2026-07-03
Unclassified MEDIUM 5.4
CVE-2026-54477

The admin panel lacks standard security headers, enabling clickjacking and cross-site scripting attacks.

Mitigation only
Fix from $1,600 2026-07-03
Unclassified CRITICAL 10.0
CVE-2026-13768

Gardyn devices expose a privileged iothubowner key. Access to this key will allow a malicious user to invoke an IoTHub Registry Manager function whic…

Mitigation only
Fix from $2,300 2026-07-03
Unclassified MEDIUM 6.9
CVE-2026-13371

An authenticated administrator can trigger a denial-of-service condition in the Fireware Management Web UI by sending malformed or crafted data to th…

Mitigation only
Fix from $1,600 2026-07-03
Entra Provisioning Service HIGH 8.8
CVE-2026-57100

Server-side request forgery (ssrf) in Microsoft Entra Provisioning Service (SyncFabric) allows an authorized attacker to elevate privileges over a ne…

Mitigation only
Fix from $1,950 2026-07-02
Exchange Online HIGH 8.8
CVE-2026-54998

Incorrect authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-02
Azure Openai HIGH 8.8
CVE-2026-45499

Server-side request forgery (ssrf) in Azure OpenAI allows an authorized attacker to elevate privileges over a network.

Mitigation only
Fix from $1,950 2026-07-02
365 Copilot CRITICAL 9.3
CVE-2026-41106

Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.

Mitigation only
Fix from $2,300 2026-07-02
Azure Synapse CRITICAL 9.8
CVE-2026-26145

Improper access control in Azure Synapse allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-02
Unclassified MEDIUM 6.5
CVE-2026-52188

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead//sub_49…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified CRITICAL 9.4
CVE-2026-52830

fast-mcp-telegram is a Telegram MCP Server. Prior to 0.19.1, fast-mcp-telegram validates HTTP Bearer tokens by joining the raw token string into a se…

No fix yet
Fix from $2,300 2026-07-02
Unclassified HIGH 7.5
CVE-2026-52192

An issue in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_445C5C component

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-52191

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_444…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-52189

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_487…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified MEDIUM 5.4
CVE-2026-59102

Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in oth…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 5.9
CVE-2026-58580

LobeChat through 2.2.9 server-database deployments are vulnerable to broken object-level authorization in MessageModel. The updateMessagePlugin, upda…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified MEDIUM 6.1
CVE-2026-58381

A flaw was found in GIMP's PSP file format parser. A double-free condition occurs in the read_layer_block() function when processing a specially craf…

Mitigation only
Fix from $1,600 2026-07-02
Unclassified HIGH 7.5
CVE-2026-58467

Cockpit CMS through 2.14.0 contains a path traversal and local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary f…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.5
CVE-2026-52187

Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-210919-161313 allows a remote attacker to cause a denial of service via the gohead/sub_483…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 8.1
CVE-2026-7311

The TinyPNG – JPEG, PNG & WebP image compression plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validati…

Mitigation only
Fix from $1,950 2026-07-02
Unclassified HIGH 7.0
CVE-2026-8699

A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insuffi…

Mitigation only
Fix from $1,950 2026-07-02