Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-74794

Scriban before 6.6.0 contains an infinite recursion vulnerability in object rendering when the ObjectRecursionLimit property defaults to unlimited. A…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74792

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a stack overflow vulnerability in nested array initializer parsing. Deeply nested array in…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 8.6
CVE-2026-74791

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to persist acros…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-74790

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to e…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74789

Scriban before 7.0.0 (affected <= 6.6.0) applies its LoopLimit constraint only to script loop statements and not to expensive iteration performed ins…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74788

Scriban before 7.0.0 (affected versions <= 6.6.0) contains an uncontrolled memory allocation vulnerability in the string.pad_left and string.pad_righ…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74787

Scriban before 7.0.0 contains an uncontrolled recursion vulnerability in the object.to_json builtin function that lacks depth limits and circular ref…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-74786

Scriban before 7.0.0 (affected versions <= 6.6.0) contains a denial-of-service vulnerability in which the LimitToString safety limit (default 1MB) ca…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-74785

Scriban before 7.0.0 contains three distinct denial-of-service vulnerabilities in expression evaluation that bypass existing safety controls through …

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 8.7
CVE-2026-74784

Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null entries without respect…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-74783

Scriban versions 6.6.0 through 7.2.0 contain a non-enforcing ExpressionDepthLimit guard that fails to stop recursive descent parsing of deeply nested…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.5
CVE-2026-73062

Scriban versions 3.0.0 through 7.2.0 contain a denial of service vulnerability in the array multiplication operator that allocates memory without enf…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-73061

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-73059

stoatchat before 0.15.0 contains a permission bypass vulnerability in the message_fetch route that checks only ViewChannel permission instead of requ…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.8
CVE-2026-73058

stoatchat versions before 0.15.0 fail to block the IPv6 unspecified address (::) in the SSRF blocklist, allowing unauthenticated attackers to bypass …

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-73057

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service by memory exhau…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-73056

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware.…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19349

Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass vi…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.5
CVE-2024-58375

OpenTofu versions 1.8.0 through 1.8.2 do not properly restrict sensitive variables and locals when users have opted into static evaluation of module …

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.3
CVE-2026-74251

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specificat…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.1
CVE-2026-74578

In the Linux kernel, the following vulnerability has been resolved: crypto: algif_skcipher - force synchronous processing on trees without ctx->stat…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.8
CVE-2024-13784

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 7.2
CVE-2026-2497

The Gallery by BestWebSoft plugin for WordPress is vulnerable to SQL Injection via the '_gallery_order_{post_id}' parameter array keys in all version…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-2357

The Bold Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'bt_bb_shortcode' shortcode in all versions …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-17608

The WP Compress – Instant Performance & Speed Optimization plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, an…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.5
CVE-2026-17087

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass in all versions up to,…

No fix yet
Fix from $4,900 2026-08-16
Unclassified HIGH 7.2
CVE-2026-13424

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via bookly_speed_up_u…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 5.3
CVE-2026-12998

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-10734

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up to, and includi…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-9767

The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all…

No fix yet
Fix from $4,000 2026-08-16