Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.0 CVE-2026-12240 The Export User Data plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the unserialize functi… Mitigation only Fix from $1,9502026-06-30 HIGH 8.6 CVE-2026-11590 The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not sanitize user-supplied array keys before using them in a SQL sta… Mitigation only Fix from $1,9502026-06-30 HIGH 8.8 CVE-2026-11589 The WP Support Plus Responsive Ticket System WordPress plugin through 9.1.2 does not properly validate uploaded files, allowing unauthenticated users… Mitigation only Fix from $1,9502026-06-30 MEDIUM 5.9 CVE-2026-11581 The Kali Forms — Contact Form & Drag-and-Drop Builder WordPress plugin before 2.4.13 does not sanitise a form field's caption before outputting it as… Mitigation only Fix from $1,6002026-06-30 MEDIUM 5.3 CVE-2026-12349 The Premium Addons for KingComposer plugin for WordPress is vulnerable to unauthorized modification and loss of data in versions up to, and including… Mitigation only Fix from $1,6002026-06-30 CRITICAL 9.8 CVE-2026-12073 The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versio… Mitigation only Fix from $2,3002026-06-30 MEDIUM 6.5 CVE-2026-11367 The PixMagix – WordPress Image Editor plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.7.2 via the m… Mitigation only Fix from $1,6002026-06-30 HIGH 7.5 CVE-2026-12243 NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `n… Nltk No fix yet Fix from $1,9502026-06-30 HIGH 7.5 CVE-2026-51219 A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial … Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-51218 A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of … Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-51221 A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via su… Mitigation only Fix from $1,9502026-06-29 HIGH 7.7 CVE-2026-34592 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, Coolify server and proje… Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-41896 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, the HMAC key is the appl… Mitigation only Fix from $1,9502026-06-29 HIGH 8.8 CVE-2026-34597 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.470, a critical Authenticated… Mitigation only Fix from $1,9502026-06-29 HIGH 8.8 CVE-2026-34594 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.471, an authenticated command… Mitigation only Fix from $1,9502026-06-29 HIGH 7.8 CVE-2026-57919 PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ a… Mitigation only Fix from $1,9502026-06-29 CRITICAL 9.6 CVE-2026-57498 Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controller… Mitigation only Fix from $2,3002026-06-29 HIGH 7.5 CVE-2026-56018 JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) … Mitigation only Fix from $1,9502026-06-29 HIGH 7.5 CVE-2026-56017 JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash.… Mitigation only Fix from $1,9502026-06-29 CRITICAL 9.1 CVE-2026-37637 An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component No fix yet Fix from $2,3002026-06-29 MEDIUM 6.5 CVE-2026-31016 Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the Identi… Mitigation only Fix from $1,6002026-06-29 CRITICAL 9.8 CVE-2026-13763 Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF mana… Application Load Balancer Mitigation only Fix from $2,3002026-06-29 CRITICAL 9.8 CVE-2026-13762 Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule bod… Cloudfront Mitigation only Fix from $2,3002026-06-29 MEDIUM 6.5 CVE-2026-13593 CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak … Mitigation only Fix from $1,6002026-06-29 HIGH 8.8 CVE-2026-57999 luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execu… Mitigation only Fix from $1,9502026-06-29 MEDIUM 5.9 CVE-2026-57959 Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatist… Mitigation only Fix from $1,6002026-06-29 MEDIUM 6.1 CVE-2026-57958 Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript i… Mitigation only Fix from $1,6002026-06-29 HIGH 8.5 CVE-2026-57955 SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injectin… Mitigation only Fix from $1,9502026-06-29 MEDIUM 6.8 CVE-2026-57948 Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie d… Mitigation only Fix from $1,6002026-06-29 HIGH 8.5 CVE-2026-57947 Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to r… Mitigation only Fix from $1,9502026-06-29