Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-14605 A vulnerability was identified in RT-Thread up to 5.0.2. Affected by this vulnerability is the function recvmsg in the library bsp/loongson/ls1cdev/l… Mitigation only Fix from $1,9502026-07-03 HIGH 7.3 CVE-2026-58379 A flaw was found in GIMP's Paint Shop Pro (PSP) file format parser. This heap buffer overflow vulnerability allows a remote attacker to cause arbitra… Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.3 CVE-2026-14604 A vulnerability was determined in Open Asset Import Library Assimp up to 6.0.4. Affected is the function Assimp::Exporter::ExportToBlob of the file c… No fix yet Fix from $1,6002026-07-03 HIGH 8.8 CVE-2026-14460 Missing Authorization vulnerability in TUBITAK BILGEM Software Technologies Research Institute pardus-software allows Argument Injection. This issue… Mitigation only Fix from $1,9502026-07-03 HIGH 8.8 CVE-2026-14459 Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Ins… Mitigation only Fix from $1,9502026-07-03 HIGH 7.4 CVE-2026-13341 A vulnerability exists in the Kong Konnect Model Context Protocol (MCP) server prior to version 1.0.0, which could allow a remote attacker to perform… Mitigation only Fix from $1,9502026-07-03 HIGH 8.5 CVE-2026-10055 In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from any client connected to the … Mitigation only Fix from $1,9502026-07-03 HIGH 8.8 CVE-2026-10054 In affected versions of Eclipse Theia (1.8.1 and later), the browser backend exposes privileged terminal RPC over WebSocket (/services/shell-terminal… Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.1 CVE-2026-4322 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Raera - Ankara Web Design and Digital Advertisi… Mitigation only Fix from $1,6002026-07-03 CRITICAL 9.8 CVE-2026-4321 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Raera - Ankara Web Design and Digital Advertisi… Mitigation only Fix from $2,3002026-07-03 MEDIUM 6.4 CVE-2026-9756 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-4804 The Zakra theme for WordPress is vulnerable to Stored Cross-Site Scripting via post meta values in all versions up to, and including, 4.2.0. This is … Mitigation only Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-47896 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 MEDIUM 5.3 CVE-2026-35159 Dell Client Platform BIOS contains an Authentication Bypass by Primary Weakness vulnerability. An unauthenticated attacker with physical access could… Mitigation only Fix from $1,6002026-07-03 MEDIUM 5.4 CVE-2026-11778 The The CURCY – Multi Currency for WooCommerce – Smoothly on WooCommerce 9.x plugin for WordPress is vulnerable to arbitrary shortcode execution in a… Mitigation only Fix from $1,6002026-07-03 MEDIUM 5.3 CVE-2026-11398 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to authorization bypass in all versions up to,… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.7 CVE-2026-8804 Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-8351 The RTMKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Advanced Heading widget's 'Background Text' parameter in version… Mitigation only Fix from $1,6002026-07-03 HIGH 7.2 CVE-2026-9148 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, … Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-47898 Improper Restriction of XML External Entity Reference vulnerability in Apache Lucene.Net (Lucene.Net.Analysis.Common library). This issue affects Ap… Lucene.net Mitigation only Fix from $2,3002026-07-03 HIGH 7.5 CVE-2026-47897 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache Lucene.Net (Lucene.Net.Replicator library). T… Lucene.net Mitigation only Fix from $1,9502026-07-03 CRITICAL 9.8 CVE-2026-14544 A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attac… Mitigation only Fix from $2,3002026-07-03 HIGH 7.5 CVE-2026-4967 In IMS, there is a possible out of bounds read due to a missing bounds check. This could lead to remote denial of service with no additional executio… Mitigation only Fix from $1,9502026-07-03 MEDIUM 6.4 CVE-2026-9626 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in v… Mitigation only Fix from $1,6002026-07-03 CRITICAL 9.1 CVE-2026-9725 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and incl… Mitigation only Fix from $2,3002026-07-03 MEDIUM 5.3 CVE-2026-9180 The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and i… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-8892 The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Addre… Mitigation only Fix from $1,6002026-07-03 MEDIUM 6.4 CVE-2026-8489 The Ultimate Member – User Profile, Registration, Login, Member Directory, Content Restriction & Membership Plugin plugin for WordPress is vulnerable… Mitigation only Fix from $1,6002026-07-03 MEDIUM 5.3 CVE-2026-12557 The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due t… Mitigation only Fix from $1,6002026-07-03 HIGH 7.5 CVE-2026-14352 The AR for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 8.40 via the 'file' parameter … Mitigation only Fix from $1,9502026-07-03