Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-72826

The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate that the scopes of a newly created API key are a subset of the caller's scopes in …

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 7.6
CVE-2026-72825

The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsCo…

No fix yet
Fix from $4,900 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72824

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API key scope-cap bypass in PagesController::guardTwigContent(). The Twig-tog…

No fix yet
Fix from $5,750 2026-08-14
Unclassified MEDIUM 5.4
CVE-2026-72823

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its private requireSuper() method…

No fix yet
Fix from $4,000 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-72822

The getgrav/grav-plugin-api Composer package before 1.0.13 (affected <= 1.0.12) fails to enforce API key scope caps on the disable2fa endpoint. Unlik…

No fix yet
Fix from $5,750 2026-08-14
Unclassified MEDIUM 5.4
CVE-2026-72821

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field option labels rendered with the…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.8
CVE-2026-72819

Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users …

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-72817

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-72816

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-co…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.9
CVE-2026-72815

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-72814

The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.9
CVE-2026-72813

actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic …

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-72812

SiYuan versions before v3.7.4 contain a missing authorization vulnerability in the /api/ref/refreshBacklink endpoint that allows anonymous readers to…

No fix yet
Fix from $4,000 2026-08-14
Unclassified CRITICAL 10.0
CVE-2026-72811

SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the backlink/mention search query (kernel/model/backlink.go), which concatenates s…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.6
CVE-2026-72810

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allows anonymous readers to receiv…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19822

A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_CN_TDC. This issue affects the function lstAdd of the file /goform/editQos of t…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.1
CVE-2025-71405

chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct r…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19821

A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. This vulnerability affects the function formSetRebootTimer of the file /goform/S…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19815

A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected by this vulnerability is the function setParentalRules of the file /cgi-bin/…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19814

A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affected is the function setMacQos of the file /cgi-bin/cstecgi.cgi of the com…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19813

A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. This impacts the function setMacFilterRules of the file /cgi-bin…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19812

A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B20200730. This affects the function UploadCustomModule of the file /cgi-bin/cstecgi.cg…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.2
CVE-2026-19794

The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 2.56 due to insufficient input s…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19811

A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20200730. The impacted element is the function setIpQosRules of the file /cgi-bin…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.5
CVE-2026-19617

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration with deeply nested structures…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.1
CVE-2026-18039

The Essential Addons for Elementor WordPress plugin before 6.7.2 does not prevent user-supplied registration fields from overwriting reserved accoun…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.5
CVE-2026-16810

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Inje…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.9
CVE-2026-16739

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of …

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.6
CVE-2026-15205

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query withi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribut…

No fix yet
Fix from $4,000 2026-08-14