Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-16745 A flaw was found in odh-dashboard, the web console component of Red Hat OpenShift AI (RHOAI). Due to incorrect network binding, a malicious actor wit… No fix yet Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-65755 Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cach… No fix yet Fix from $1,9502026-07-23 HIGH 7.5 CVE-2026-65754 Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the s… No fix yet Fix from $1,9502026-07-23 HIGH 8.1 CVE-2026-65757 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Modules Anywhere extension - The editor popup could expose … No fix yet Fix from $1,9502026-07-23 HIGH 8.2 CVE-2026-65758 Joomla Extension - tassos.gr - Sensitive data exposure in Convert Forms extension 2.5.0-5.2.2 - The front-end Submissions view did not enforce access… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.1 CVE-2026-65756 Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript. No fix yet Fix from $1,6002026-07-23 HIGH 8.8 CVE-2026-64876 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consiste… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-65431 Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation… Mitigation only Fix from $2,3002026-07-23 HIGH 7.5 CVE-2026-65430 Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a cred… No fix yet Fix from $1,9502026-07-23 MEDIUM 6.5 CVE-2026-64875 Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this… No fix yet Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-64874 Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs. No fix yet Fix from $2,3002026-07-23 MEDIUM 6.5 CVE-2026-65713 Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension - Modals gallery paths could enumerate unintended directories. No fix yet Fix from $1,6002026-07-23 MEDIUM 6.2 CVE-2026-65712 Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site … No fix yet Fix from $1,6002026-07-23 CRITICAL 9.8 CVE-2026-64873 Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. No fix yet Fix from $2,3002026-07-23 MEDIUM 6.5 CVE-2026-64872 Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directo… No fix yet Fix from $1,6002026-07-23 HIGH 7.5 CVE-2026-64799 Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image UR… No fix yet Fix from $1,9502026-07-23 MEDIUM 5.4 CVE-2026-64871 Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Administrator URL purges did not … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-16078 The WCPOS – Point of Sale (POS) plugin for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-15906 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in all … No fix yet Fix from $1,6002026-07-23 MEDIUM 5.3 CVE-2026-15827 The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the /wp-json/gutenkit/v1/m… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15794 The Grid/List View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'position' Shortcode Attribute in all versio… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-15761 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_event_filter' parameter in all ver… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15646 The Brands for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'style' Shortcode Attribute in all versions up to, a… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.5 CVE-2026-15448 The Tickera – Sell Tickets & Manage Events plugin for WordPress is vulnerable to generic SQL Injection via the 'tc_order_status_filter' parameter in … No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15404 The Lpagery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in versions up to, and including, 2.5.7. This is due to… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.4 CVE-2026-15394 The Header Footer Script Adder – Insert Code in Header, Body & Footer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'asm_code… No fix yet Fix from $1,6002026-07-23 MEDIUM 6.3 CVE-2026-15348 The Premium Packages – Sell Digital Products Securely plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includin… No fix yet Fix from $1,6002026-07-23 HIGH 8.8 CVE-2026-15017 The MDJM Event Management plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.7.8.4. This is due to mi… No fix yet Fix from $1,9502026-07-23 CRITICAL 9.8 CVE-2026-15015 The MountDev AI MCP Connector for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.6.1. T… Mitigation only Fix from $2,3002026-07-23 CRITICAL 9.8 CVE-2026-15011 The Customer Support Ticket System & Helpdesk plugin for WordPress is vulnerable to Code Injection via the 'path' parameter in all versions up to, an… No fix yet Fix from $2,3002026-07-23