Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-12976 The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-assistant requests against tha… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-18961 The Social Login, Passkeys, Magic Link & Email OTP – Passwordless Login by VentraConnect plugin for WordPress is vulnerable to Authentication Bypass … No fix yet Fix from $4,9002026-08-12 MEDIUM 6.3 CVE-2025-15685 A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnerability is an unknown functionality of the component freeDiameter. This manipula… No fix yet Fix from $4,0002026-08-12 HIGH 7.7 CVE-2026-73122 A flaw was found in the multicloud-operators-channel component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows a compromise… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.9 CVE-2026-72526 A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.6 CVE-2026-70398 A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated u… No fix yet Fix from $5,7502026-08-12 HIGH 7.7 CVE-2026-66878 A flaw was found in multicloud-operators-subscription. A privileged user, specifically a namespace administrator capable of creating Channel and Subs… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.4 CVE-2026-64927 A flaw was found in the multicloud-operators-channel component. This vulnerability allows a user with specific permissions to manipulate how the syst… No fix yet Fix from $4,0002026-08-12 HIGH 8.2 CVE-2026-6484 In an UEFI, Lack of verified boot to certain FV may cause arbitrary code execution. No fix yet Fix from $4,9002026-08-12 HIGH 7.1 CVE-2026-68447 In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size CRIU checkpo… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-68446 In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate vmw_surface_metadata::array_size This field comes from use… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-68445 In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Prevent shader BO mappings from becoming writable vc4_gem_object_mmap(… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-68442 In the Linux kernel, the following vulnerability has been resolved: btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps When btrfs_drop… No fix yet Fix from $4,9002026-08-12 HIGH 7.8 CVE-2026-68440 In the Linux kernel, the following vulnerability has been resolved: net: txgbe: fix heap overflow when reading module EEPROM txgbe_read_eeprom_host… No fix yet Fix from $4,9002026-08-12 HIGH 8.6 CVE-2026-68433 In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply()… No fix yet Fix from $4,9002026-08-12 HIGH 8.8 CVE-2026-68432 In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel change… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.1 CVE-2026-68431 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applie… No fix yet Fix from $5,7502026-08-12 HIGH 8.6 CVE-2026-73247 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/core/runners/pebble/functions/Ht… No fix yet Fix from $4,9002026-08-11 HIGH 7.5 CVE-2026-73246 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's worker/src/main/java/io/kestra/worker/endpoint/WorkerEndp… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-73245 Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/application.yml serves Micronaut m… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.8 CVE-2026-68067 The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the accoun… No fix yet Fix from $5,7502026-08-11 CRITICAL 9.1 CVE-2026-67568 The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which … No fix yet Fix from $5,7502026-08-11 HIGH 7.4 CVE-2026-67558 The Mira Android companion app v4.5.15.4 identifies the paired Mira hormone analyzer by performing a substring match against the BLE advertisement na… No fix yet Fix from $4,9002026-08-11 HIGH 8.8 CVE-2026-66875 In the Mira hormone monitor device firmware v1.7.1.47 build 01070147, a remote unauthenticated attacker within BLE range (approximately 10–30 meters)… No fix yet Fix from $4,9002026-08-11 MEDIUM 5.3 CVE-2026-66340 The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout after repeated failed login a… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-66098 The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the device to reboot into bootload… No fix yet Fix from $4,0002026-08-11 CRITICAL 9.6 CVE-2026-5917 libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all… No fix yet Fix from $5,7502026-08-11 HIGH 7.5 CVE-2026-29036 cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved name or reference vulnerability in the decode_pointer_inplace() function within c… No fix yet Fix from $4,9002026-08-11 MEDIUM 6.5 CVE-2026-18710 A MongoDB driver component could write sensitive configuration information, including a credential used for outbound network connectivity, to applica… No fix yet Fix from $4,0002026-08-11 MEDIUM 6.5 CVE-2026-66832 When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is appended to the URL as a query s… No fix yet Fix from $4,0002026-08-11