Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-54823

Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.

Mitigation only
Fix from $2,300 2026-06-25
Unclassified HIGH 8.5
CVE-2026-54822

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.4
CVE-2026-54821

Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.9
CVE-2026-52690

Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that …

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-42390

An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-42389

This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers.

No fix yet
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.9
CVE-2026-42388

Incomplete validation of the SOA record present in a catalog zone might lead to a crash.

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.9
CVE-2026-42387

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input …

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-40012

ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 8.4
CVE-2026-2815

Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-27366

Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-40211

An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will …

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 5.3
CVE-2026-40209

An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by s…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 7.5
CVE-2026-33612

A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 8.2
CVE-2026-56091

When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. Th…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.4
CVE-2026-54226

A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0…

No fix yet
Fix from $1,600 2026-06-25
Unclassified CRITICAL 10.0
CVE-2026-46752

Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are r…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-46751

A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0…

No fix yet
Fix from $1,600 2026-06-25
Unclassified CRITICAL 9.4
CVE-2026-41566

Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are re…

Mitigation only
Fix from $2,300 2026-06-25
Unclassified MEDIUM 5.5
CVE-2026-56129

Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A log…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 7.5
CVE-2026-12937

The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via …

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 7.5
CVE-2026-9702

The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce ord…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified HIGH 8.8
CVE-2026-5305

The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replace…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-10824

The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthentic…

Mitigation only
Fix from $1,600 2026-06-25
GitLab HIGH 7.5
CVE-2026-12053

GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-2508

The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and incl…

Mitigation only
Fix from $1,600 2026-06-25
Unclassified MEDIUM 6.5
CVE-2026-12079

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 …

Mitigation only
Fix from $1,600 2026-06-25
Unclassified HIGH 7.5
CVE-2026-12077

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to,…

Mitigation only
Fix from $1,950 2026-06-25
Unclassified MEDIUM 6.4
CVE-2026-10833

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t…

Mitigation only
Fix from $1,600 2026-06-25
Sed HIGH 8.8
CVE-2026-9155

OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t…

Mitigation only
Fix from $1,950 2026-06-25