Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-18032 The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the … No fix yet Fix from $1,9502026-08-09 MEDIUM 5.3 CVE-2026-17014 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions,… No fix yet Fix from $1,6002026-08-09 HIGH 8.1 CVE-2026-17017 The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an A… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.5 CVE-2026-16992 The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that r… No fix yet Fix from $1,6002026-08-09 HIGH 7.5 CVE-2026-16988 The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested list… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.1 CVE-2026-16032 The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before stori… No fix yet Fix from $1,6002026-08-09 CRITICAL 9.8 CVE-2026-15038 The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remot… No fix yet Fix from $2,3002026-08-09 MEDIUM 5.3 CVE-2026-19334 A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. … No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19333 A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by… No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19332 A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_… No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19331 A vulnerability was identified in bazylhorsey obsidian-mcp-server 1.0.0. This affects the function readCanvas/writeCanvas of the file src/services/Ca… No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19330 A vulnerability was determined in angrysky56 advanced-reasoning-mcp 1.0.0. The impacted element is the function create_system_json/create_library to … No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19329 A vulnerability was found in andreahaku codex_mcp up to 1ff521cc6cc57cfe56ddef946c644b8534771390. The affected element is an unknown function of the … No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19325 A security vulnerability has been detected in IncomeStreamSurfer roo-code-memory-bank-mcp-server up to 9dcb2fb5e6b65a35ac1983885a6d4e5621a0081e. This… No fix yet Fix from $1,6002026-08-09 CRITICAL 9.8 CVE-2026-71993 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the openvpn function that allows remote attackers to … No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71992 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the macfilter function that allows remote attackers t… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71991 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration … No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71990 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration tha… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71989 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the porTrigger function that allows remote attackers … No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71988 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the portFw function that allows remote attackers to e… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71987 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the alg function that allows remote attackers to exec… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71986 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to exec… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71985 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attacke… No fix yet Fix from $2,3002026-08-09 CRITICAL 9.8 CVE-2026-71984 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the urlfilter function that allows remote attackers t… No fix yet Fix from $2,3002026-08-09 MEDIUM 5.3 CVE-2026-19323 A security flaw has been discovered in azer react-analyzer-mcp up to 335f2a3585f265e2e88352b59b10d3b478d678b0. Affected by this vulnerability is the … No fix yet Fix from $1,6002026-08-09 CRITICAL 9.8 CVE-2026-71983 MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the wps.cgi interface that allows remote attackers to… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71958 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the quicksetup… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71957 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi in… No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71956 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the app.cgi … No fix yet Fix from $2,3002026-08-08 CRITICAL 9.8 CVE-2026-71955 D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a command injection vulnerability in the /boafrm/… No fix yet Fix from $2,3002026-08-08