Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.4 CVE-2026-15285 The Plus Addons for Elementor plugin for WordPress was vulnerable to Authenticated (Contributor+) Stored Cross-Site Scripting via the Button widget's… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.4 CVE-2026-15284 The King Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'form_page_id' parameter in versions up to, a… Mitigation only Fix from $1,6002026-07-10 HIGH 7.5 CVE-2026-15288 The SureForms – Drag and Drop Form Builder for WordPress plugin for WordPress is vulnerable to Improper Input Validation in all versions up to, and i… Mitigation only Fix from $1,9502026-07-10 CRITICAL 9.8 CVE-2026-15282 The Instant Appointment plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'insapp_upload_image_… Mitigation only Fix from $2,3002026-07-10 MEDIUM 5.4 CVE-2026-5069 The Fluent Forms plugin for WordPress is vulnerable to incorrect authorization via the 'subscription_id' parameter in versions up to, and including, … Mitigation only Fix from $1,6002026-07-10 HIGH 8.2 CVE-2026-54423 In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_r… Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.5 CVE-2026-44918 OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization. Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-11818 The WPCafe – Restaurant Menu, Online Food Ordering & Table Booking System plugin for WordPress is vulnerable to authorization bypass in all versions … Mitigation only Fix from $1,6002026-07-10 HIGH 8.8 CVE-2026-15070 The Salon Booking System – Free Version plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 10.30.… Mitigation only Fix from $1,9502026-07-10 HIGH 7.2 CVE-2026-13430 The Post Export Import with Media plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.13.1 via the im… Mitigation only Fix from $1,9502026-07-10 MEDIUM 6.1 CVE-2026-11392 The WP Hotel Booking plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'check_in_date' and 'check_out_date' parameters in … Mitigation only Fix from $1,6002026-07-10 MEDIUM 5.4 CVE-2026-15320 A vulnerability was detected in Sipeed PicoClaw up to 0.2.9. This vulnerability affects the function rt.ReloadConfig of the file pkg/channels/pico/pi… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15318 A weakness has been identified in Sipeed PicoClaw up to 0.2.9. Affected by this issue is some unknown functionality of the file pkg/channels/mqtt/mqt… Mitigation only Fix from $1,6002026-07-10 MEDIUM 6.3 CVE-2026-15317 A security flaw has been discovered in Sipeed PicoClaw up to 0.2.9. Affected by this vulnerability is the function WebFetchTool.Execute of the file p… Mitigation only Fix from $1,6002026-07-10 HIGH 8.1 CVE-2026-54771 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.3, a Langroid application exposing a chat inter… Mitigation only Fix from $1,9502026-07-10 CRITICAL 10.0 CVE-2026-54769 Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical Sandbox Escape … Mitigation only Fix from $2,3002026-07-10 CRITICAL 9.3 CVE-2026-54760 Langroid is a framework for building large-language-model-powered applications. Prior to version 0.65.1, the `SQLChatAgent` SQL-injection mitigation,… Mitigation only Fix from $2,3002026-07-10 HIGH 8.1 CVE-2026-12598 The LoginPress Pro plugin for WordPress is vulnerable to authentication bypass in versions up to and including 6.2.3 via the Spotify Social Login add… Mitigation only Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-12597 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via the GitHub OAuth callback in versions up to, and including, 6.2.3.… Mitigation only Fix from $1,9502026-07-10 HIGH 8.1 CVE-2026-12595 The LoginPress Pro plugin for WordPress is vulnerable to Authentication Bypass via Unverified OAuth Email in all versions up to and including 6.2.3. … Mitigation only Fix from $1,9502026-07-10 MEDIUM 5.4 CVE-2026-58144 Cotonti Siena 0.9.26 and earlier contains a stored cross-site scripting vulnerability that allows authenticated users with PFS access to inject arbit… Mitigation only Fix from $1,6002026-07-09 HIGH 8.8 CVE-2026-58143 Cotonti Siena 0.9.26 and earlier contains a cross-site request forgery vulnerability that allows unauthenticated attackers to modify administrator co… Mitigation only Fix from $1,9502026-07-09 MEDIUM 5.9 CVE-2026-57030 A Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the packet forwarding engine (PFE) of … Junos Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-57029 A Missing Synchronization vulnerability in the flow collector handler of Juniper Networks Junos OS Evolved on QFX Series allows an adjacent, unauthen… Junos Os Evolved Mitigation only Fix from $1,6002026-07-09 MEDIUM 5.3 CVE-2026-57021 An Out-of-bounds Write vulnerability in the http-gatekeeper (http-gk) of Juniper Networks Junos OS on SRX Series allows an unauthenticated, network-b… Junos Mitigation only Fix from $1,6002026-07-09 HIGH 7.5 CVE-2026-57023 An Improper Validation of Specified Quantity in Input vulnerability in the TCP proxy plugin of Juniper Networks Junos OS on MX Series with SPC3, and … Junos Mitigation only Fix from $1,9502026-07-09 MEDIUM 5.3 CVE-2026-55605 DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.8.0, the self-hosted HTTP transport of `@ariku… Mitigation only Fix from $1,6002026-07-09 HIGH 8.6 CVE-2026-55604 DeepSeek MCP Server is an MCP server for DeepSeek V4. Starting in version 1.4.2 and prior to version 1.7.0, the process-global `SessionStore` accepts… Mitigation only Fix from $1,9502026-07-09 HIGH 7.5 CVE-2026-38076 An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a cra… Mitigation only Fix from $1,9502026-07-09 MEDIUM 5.5 CVE-2026-33802 A Missing Authorization vulnerability in the CLI of Juniper Networks Junos OS on EX Series allows a local, authenticated attacker to cause a Denial-o… Junos Mitigation only Fix from $1,6002026-07-09