Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-15813 A vulnerability was found in the network packet de-fragmentation engine of kronosnet (Version affected <= 1.34). The internal reassembly code does no… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-15588 A denial-of-service and resource exhaustion vulnerability exists within the `GDBus` component of GLib. The `gdbusauth` authentication mechanism fails… No fix yet Fix from $1,6002026-07-20 HIGH 7.2 CVE-2026-14448 An high privileged remote attacker can exploit an authenticated OS command injection vulnerability in the system_certificates view due to improper ne… No fix yet Fix from $1,9502026-07-20 HIGH 8.2 CVE-2026-13577 Dancer2 versions through 2.1.0 for Perl generate insecure session ids when required CSPRNG modules are unavailable. Dancer2::Core::Role::SessionFact… No fix yet Fix from $1,9502026-07-20 HIGH 7.1 CVE-2026-9833 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters b… No fix yet Fix from $1,9502026-07-20 HIGH 7.5 CVE-2026-6656 Crypt::Password versions through 0.28 for Perl are susceptible to timing attacks. The check_password method uses the built-in eq operator. This allo… No fix yet Fix from $1,9502026-07-20 CRITICAL 9.8 CVE-2026-16235 Crypt::Password versions through 0.28 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is pr… No fix yet Fix from $2,3002026-07-20 HIGH 8.1 CVE-2026-13142 The Social Login, Passkeys, Magic Link & Email OTP WordPress plugin before 1.4.1 does not enforce rate limiting or a working attempt lockout on its … No fix yet Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-13432 The ThumbPress WordPress plugin before 6.2.2 does not perform a capability check on one of its AJAX actions, allowing authenticated users with subsc… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.4 CVE-2026-13156 The MailerSend WordPress plugin before 1.0.8 does not perform a nonce check on its configuration-delete action (it verifies the manage_options capab… No fix yet Fix from $1,6002026-07-20 CRITICAL 9.1 CVE-2026-13147 The Kirki WordPress plugin before 6.0.12 does not validate a user-supplied URL before requesting it server-side, allowing unauthenticated attackers … No fix yet Fix from $2,3002026-07-20 MEDIUM 6.5 CVE-2026-12973 The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-12972 The PayPlus Payment Gateway WordPress plugin before 8.2.2 does not perform authorization or order-ownership validation in one of its AJAX actions ava… No fix yet Fix from $1,6002026-07-20 HIGH 7.1 CVE-2026-12970 The LearnPress WordPress plugin before 4.4.1 does not escape a search parameter before reflecting it into an HTML attribute, leading to Reflected Cr… No fix yet Fix from $1,9502026-07-20 MEDIUM 6.5 CVE-2026-12898 The All-in-One WP Migration and Backup WordPress plugin before 7.106 does not properly sanitise a user-supplied value before using it to build a file… No fix yet Fix from $1,6002026-07-20 MEDIUM 5.3 CVE-2026-12723 The Kirki WordPress plugin before 6.0.12 does not perform any authorisation check on one of its REST routes, allowing unauthenticated users to overw… No fix yet Fix from $1,6002026-07-20 HIGH 7.5 CVE-2026-12592 The SlimStat Analytics WordPress plugin before 5.5.0 does not escape a visitor-controlled geolocation value before outputting it in its admin analyti… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.3 CVE-2026-11868 The WP Travel WordPress plugin before 11.7.1 does not perform capability or ownership checks on its booking cancellation action, which is also expos… No fix yet Fix from $1,6002026-07-20 HIGH 8.6 CVE-2026-11349 The Modern Event Calendar Pro WordPress plugin before 7.34.0, Modern Events Calendar Lite WordPress plugin before 7.34.0 do not sanitise and escape a… No fix yet Fix from $1,9502026-07-20 HIGH 8.8 CVE-2026-10081 The Unlimited Elements For Elementor WordPress plugin before 2.0.11 does not sanitize or escape Google review content fetched from the Serp API befor… No fix yet Fix from $1,9502026-07-20 MEDIUM 5.4 CVE-2026-45138 CI4MS is a CodeIgniter 4-based content management system skeleton. Prior to version 0.31.9.0, the custom `html_purify` validation rule used to saniti… No fix yet Fix from $1,6002026-07-20 HIGH 7.8 CVE-2026-12484 A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras… No fix yet Fix from $1,9502026-07-19 HIGH 7.8 CVE-2026-64086 In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer adm1266… No fix yet Fix from $1,9502026-07-19 HIGH 7.8 CVE-2026-64084 In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR adm1266… No fix yet Fix from $1,9502026-07-19 HIGH 7.8 CVE-2026-64082 In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_g… No fix yet Fix from $1,9502026-07-19 HIGH 8.4 CVE-2026-64081 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Validate framework notification message layout Framework not… No fix yet Fix from $1,9502026-07-19 CRITICAL 9.3 CVE-2026-64080 In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Snapshot notifier callbacks under lock Both notification han… Mitigation only Fix from $2,3002026-07-19 HIGH 7.8 CVE-2026-64078 In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: add and use xtables_unregister_table_exit Previous change … No fix yet Fix from $1,9502026-07-19 HIGH 7.8 CVE-2026-64077 In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: move to two-stage removal scheme Like previous patches for… No fix yet Fix from $1,9502026-07-19 HIGH 7.8 CVE-2026-64076 In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: eb_tables: close module init race sashiko reports for unrela… No fix yet Fix from $1,9502026-07-19