Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-54823 Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions. Mitigation only Fix from $2,3002026-06-25 HIGH 8.5 CVE-2026-54822 Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions. Mitigation only Fix from $1,9502026-06-25 HIGH 7.4 CVE-2026-54821 Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions. Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.9 CVE-2026-52690 Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that … Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-42390 An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation. Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-42389 This fix provides extra hardening for the 5.4.x branch by doing extra validation of incoming answers from authoritative servers. No fix yet Fix from $1,6002026-06-25 MEDIUM 5.9 CVE-2026-42388 Incomplete validation of the SOA record present in a catalog zone might lead to a crash. Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.9 CVE-2026-42387 A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input … Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-40012 ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled; Mitigation only Fix from $1,6002026-06-25 HIGH 8.4 CVE-2026-2815 Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-27366 Unauthenticated Broken Access Control in MainWP Child <= 6.1.1 versions. Mitigation only Fix from $1,9502026-06-25 MEDIUM 5.3 CVE-2026-40211 An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will … Mitigation only Fix from $1,6002026-06-25 MEDIUM 5.3 CVE-2026-40209 An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by s… Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-33612 A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning. Mitigation only Fix from $1,9502026-06-25 HIGH 8.2 CVE-2026-56091 When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. Th… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.4 CVE-2026-54226 A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.6.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0… No fix yet Fix from $1,6002026-06-25 CRITICAL 10.0 CVE-2026-46752 Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0. Users are r… Mitigation only Fix from $2,3002026-06-25 MEDIUM 5.5 CVE-2026-46751 A vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0. Users are recommended to upgrade to version 2.16.0… No fix yet Fix from $1,6002026-06-25 CRITICAL 9.4 CVE-2026-41566 Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks. This issue affects Apache Kvrocks: 2.8.0. Users are re… Mitigation only Fix from $2,3002026-06-25 MEDIUM 5.5 CVE-2026-56129 Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A log… Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-12937 The Tourfic – AI Powered Travel Booking, Hotel Booking & Car Rental WordPress Plugin plugin for WordPress is vulnerable to generic SQL Injection via … Mitigation only Fix from $1,9502026-06-25 HIGH 7.5 CVE-2026-9702 The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce ord… Mitigation only Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-5305 The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replace… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-10824 The Masteriyo LMS WordPress plugin before 2.2.1 does not perform authorization checks in a course-progress REST API controller, allowing unauthentic… Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-12053 GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to… GitLab Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-2508 The Gravity Forms Booking plugin for WordPress is vulnerable to time-based SQL Injection via the ‘staff_id’ parameter in all versions up to, and incl… Mitigation only Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-12079 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 … Mitigation only Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-12077 The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to,… Mitigation only Fix from $1,9502026-06-25 MEDIUM 6.4 CVE-2026-10833 The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via t… Mitigation only Fix from $1,6002026-06-25 HIGH 8.8 CVE-2026-9155 OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via t… Sed Mitigation only Fix from $1,9502026-06-25