Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-6639 The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and includin… No fix yet Fix from $1,9502026-08-05 HIGH 8.2 CVE-2026-6627 The WPFormify – Stripe Payments with Form and Checkout plugin for WordPress is vulnerable to unauthorized modification and deletion of Stripe payment… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-6147 The LightSync Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the rest_replace_media() functi… No fix yet Fix from $1,9502026-08-05 HIGH 7.3 CVE-2026-6079 The Material Dashboard plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on the amd… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-6020 The ShopLentor plugin for WordPress is vulnerable to arbitrary function execution via the woolentoropt/v1/custom-action REST API endpoint in all vers… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64581 In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() cle… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64580 In the Linux kernel, the following vulnerability has been resolved: xfrm6: clear dst.dev on error to avoid double netdev_put in xfrm6_fill_dst() On… No fix yet Fix from $1,9502026-08-05 HIGH 8.2 CVE-2026-64578 In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate compound request size before reading StructureSize2 When ksmbd … No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-64577 In the Linux kernel, the following vulnerability has been resolved: gtp: check skb_pull_data() return in gtp1u_send_echo_resp() gtp1u_send_echo_res… No fix yet Fix from $1,9502026-08-05 HIGH 7.1 CVE-2026-64576 In the Linux kernel, the following vulnerability has been resolved: nexthop: initialize extack in nh_res_bucket_migrate() nh_res_bucket_migrate() p… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64575 In the Linux kernel, the following vulnerability has been resolved: bpf: tcp: fix double sock release on batch realloc bpf_iter_tcp_batch() release… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64574 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: tear down new links on vif update error path When ieee80211_vif… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64570 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_f… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64568 In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee802… No fix yet Fix from $1,9502026-08-05 HIGH 7.8 CVE-2026-64567 In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 f… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-64566 In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_sk… No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-61483 ** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project … Lucy No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-61486 ** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro… Lucy No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-61485 ** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versio… Lucy No fix yet Fix from $1,9502026-08-05 CRITICAL 9.8 CVE-2026-61484 ** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th… Lucy Mitigation only Fix from $2,3002026-08-05 CRITICAL 9.1 CVE-2026-5581 The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including… No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-59675 When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. B… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.3 CVE-2026-55998 The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a clust… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-55997 Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in … Mitigation only Fix from $1,9502026-08-05 MEDIUM 6.8 CVE-2026-55747 The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonica… No fix yet Fix from $1,6002026-08-05 HIGH 8.3 CVE-2026-55739 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->compan… No fix yet Fix from $1,9502026-08-05 HIGH 8.1 CVE-2026-54418 Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on … No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-54416 Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php',… No fix yet Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-4431 The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_pos… No fix yet Fix from $2,3002026-08-05 HIGH 7.5 CVE-2026-18881 The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` paramet… No fix yet Fix from $1,9502026-08-05