Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2026-8790 The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in a… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-8761 The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorizat… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-7753 The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cos… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.0 CVE-2026-71192 In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.0 CVE-2026-71191 In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned UR… No fix yet Fix from $1,6002026-08-05 HIGH 8.7 CVE-2026-71190 In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.7 CVE-2026-66839 NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticat… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.7 CVE-2026-66344 NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authentica… No fix yet Fix from $1,6002026-08-05 HIGH 7.1 CVE-2026-55707 In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard … No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-18902 A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-18322 The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to … No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-16143 The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field o… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-15941 The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. … No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-15918 VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls h… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-11421 The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilt… No fix yet Fix from $1,6002026-08-05 HIGH 7.2 CVE-2026-18901 A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API.… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-18900 A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This man… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-18898 A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The … No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-18907 Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in t… No fix yet Fix from $1,9502026-08-05 HIGH 8.8 CVE-2026-18897 A vulnerability was identified in UTT HiPER 1250GW up to v3.2.7-210907-180535. The impacted element is the function strcpy of the file /goform/getOne… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.3 CVE-2026-18896 A vulnerability was determined in lavkush-maurya Student-Registration-System 1.0. The affected element is an unknown function of the file /student/ch… No fix yet Fix from $1,6002026-08-05 HIGH 8.8 CVE-2026-18895 A vulnerability was found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Impacted is the function strcpy of the file /goform/APSecurity_5g. Performin… No fix yet Fix from $1,9502026-08-05 HIGH 7.3 CVE-2026-18859 A vulnerability was identified in ESAFENET CDG up to 20260615. Affected is an unknown function of the file /CDGServer3/ukey/usbkey;logindojojs. Such … No fix yet Fix from $1,9502026-08-05 HIGH 7.3 CVE-2026-18854 A vulnerability has been found in Shandong Hoteam PDM Product Data Management System up to 8.3.10. The impacted element is the function GetStoredClas… No fix yet Fix from $1,9502026-08-05 MEDIUM 5.3 CVE-2026-18853 A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the function t5.l.c of the componen… No fix yet Fix from $1,6002026-08-05 MEDIUM 6.3 CVE-2026-18818 A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views… No fix yet Fix from $1,6002026-08-04 HIGH 7.5 CVE-2026-67862 open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attack… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67860 open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backe… No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67861 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component No fix yet Fix from $1,9502026-08-04 HIGH 7.5 CVE-2026-67859 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling. No fix yet Fix from $1,9502026-08-04