Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.3
CVE-2026-13487

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13486

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.3
CVE-2026-13485

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Perform…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.6
CVE-2026-58056

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 7.2
CVE-2026-58054

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers th…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified CRITICAL 9.9
CVE-2026-58053

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig …

Mitigation only
Fix from $2,300 2026-06-28
Unclassified HIGH 8.6
CVE-2026-58049

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary c…

Mitigation only
Fix from $1,950 2026-06-28
Unclassified HIGH 8.1
CVE-2026-8095

The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. Th…

Mitigation only
Fix from $1,950 2026-06-28
FreeBSD HIGH 7.8
CVE-2026-49416

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size c…

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD HIGH 7.8
CVE-2026-49414

The ELF image activator cleared per-process ASLR preference flags for setuid binaries after the code that computes the PIE base address, rather than …

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD HIGH 7.0
CVE-2026-49417

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory could …

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD HIGH 7.1
CVE-2026-49413

The Linuxulator determined whether a binary was set-user-ID or set-group-ID by checking the P_SUGID process flag. During execve(2), this flag is not…

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD HIGH 7.8
CVE-2026-49412

The kernel handler for IPV6_MSFILTER dropped a serializing lock in order to copy the source-filter list from userspace, then reacquired the lock. Du…

Mitigation only
Fix from $1,950 2026-06-27
FreeBSD MEDIUM 6.5
CVE-2026-45259

sigqueue(2) was marked as permitted in capability mode with the introduction of Capsicum in 2011, but the implementation of kern_sigqueue did not inc…

Mitigation only
Fix from $1,600 2026-06-27
FreeBSD HIGH 7.8
CVE-2026-45258

dsp_mmap_single() validated the requested mapping by checking the sum of the user-supplied offset and length against the buffer size. This addition …

Mitigation only
Fix from $1,950 2026-06-27
Unclassified MEDIUM 5.3
CVE-2026-9242

The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication By…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.5
CVE-2026-3462

The Frisbii Pay plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the 'upload_csv' and 'pro…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-13295

The Page Builder by SiteOrigin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via panels_data Parameter in all versions up to, and…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 5.3
CVE-2026-12432

The WP Full Stripe Free plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 8.4.3 via the wpfs_update_faile…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-11783

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Stored C…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-11597

The Surbma | Infusionsoft Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'infusionsoft-form' shortcode in versio…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.1
CVE-2026-13245

The MaxButtons – Create buttons plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'view' parameter in all versions up to, …

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 5.3
CVE-2026-12404

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, …

Mitigation only
Fix from $1,600 2026-06-27
Unclassified HIGH 8.1
CVE-2026-10820

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not …

Mitigation only
Fix from $1,950 2026-06-27
Unclassified CRITICAL 9.8
CVE-2026-12415

The Invoice Generator plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the pravel_invoice_edit_account…

Mitigation only
Fix from $2,300 2026-06-27
Unclassified MEDIUM 6.4
CVE-2026-13335

The CodePeople Post Map for Google Maps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cpm_point' Post Meta in all versions u…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.5
CVE-2026-13333

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via 'query[select]' Parameter…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified MEDIUM 6.5
CVE-2026-13331

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to generic SQL Injection via the 'search' parameter in…

Mitigation only
Fix from $1,600 2026-06-27
Unclassified HIGH 7.2
CVE-2026-56414

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed,…

Mitigation only
Fix from $1,950 2026-06-26
Unclassified HIGH 7.2
CVE-2026-55975

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate gener…

Mitigation only
Fix from $1,950 2026-06-26