Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.4
CVE-2026-57291

Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an att…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 8.4
CVE-2026-42450

OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-56338

Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authent…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-56337

Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers …

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.5
CVE-2026-56302

Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.1
CVE-2026-56257

Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-bra…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-56256

Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g.,…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.2
CVE-2026-56245

Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unau…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.1
CVE-2026-56244

Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on …

Mitigation only
Fix from $1,950 2026-06-24
Unclassified CRITICAL 9.1
CVE-2026-56237

Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, …

Mitigation only
Fix from $2,300 2026-06-24
Unclassified HIGH 8.8
CVE-2026-56232

Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareK…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.6
CVE-2026-56231

Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.7
CVE-2026-56223

Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitr…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-12242

The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' at…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.1
CVE-2025-71361

picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.1
CVE-2025-71354

picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Atta…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.9
CVE-2026-10745

Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tamperi…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 8.8
CVE-2026-7761

The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.1…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.6
CVE-2026-56052

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Bl…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.7
CVE-2026-9710

The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce ne…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.7
CVE-2026-9709

The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to di…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.2
CVE-2026-9643

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 6.4
CVE-2026-9620

The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-9612

The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified HIGH 7.5
CVE-2026-9179

The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified HIGH 7.5
CVE-2026-9178

The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the…

Mitigation only
Fix from $1,950 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-9175

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 5.3
CVE-2026-9172

The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due t…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.1
CVE-2026-8905

The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due t…

Mitigation only
Fix from $1,600 2026-06-24
Unclassified MEDIUM 6.4
CVE-2026-8896

The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such …

Mitigation only
Fix from $1,600 2026-06-24