Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-57291 Missing permission checks in Jenkins Gitee Plugin 1288.v18b_deb_c9069b_ and earlier allow attackers with Overall/Read permission to connect to an att… Mitigation only Fix from $1,6002026-06-24 HIGH 8.4 CVE-2026-42450 OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-56338 Capgo before 12.128.2 contains a denial of service vulnerability in the /auth/v1/otp endpoint that prevents email verification for two-factor authent… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-56337 Capgo before 12.128.2 contains an information disclosure vulnerability in the public.exist_app_v2 RPC function that allows unauthenticated attackers … Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.5 CVE-2026-56302 Capgo before 12.128.2 contains an unsecured images bucket lacking any row level security controls, allowing unauthenticated attackers to read, insert… Mitigation only Fix from $1,6002026-06-24 HIGH 7.1 CVE-2026-56257 Capgo before 12.128.2 allows direct patching of public.apps.owner_org through PostgREST, bypassing the transfer_app() workflow and creating split-bra… Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-56256 Capgo before 12.128.2 enforces mandatory two-factor authentication only at the UI level. Sensitive Organization (ORG) management API endpoints (e.g.,… Mitigation only Fix from $1,9502026-06-24 HIGH 8.2 CVE-2026-56245 Supabase Capgo before 12.128.2 contains an authorization bypass vulnerability in the SECURITY DEFINER record_build_time RPC function that allows unau… Mitigation only Fix from $1,9502026-06-24 HIGH 7.1 CVE-2026-56244 Capgo before 12.128.2 allows non-admin API keys to read webhook signing secrets via Supabase REST due to insufficient row-level security policies on … Mitigation only Fix from $1,9502026-06-24 CRITICAL 9.1 CVE-2026-56237 Capgo before 12.128.2 contains a broken authentication vulnerability in its API key generation mechanism. API keys are exposed in frontend requests, … Mitigation only Fix from $2,3002026-06-24 HIGH 8.8 CVE-2026-56232 Capgo before 12.128.2 fails to enforce limited_to_orgs and limited_to_apps constraints on subkeys provided via x-limited-key-id header in middlewareK… Mitigation only Fix from $1,9502026-06-24 HIGH 7.6 CVE-2026-56231 Capgo before 12.128.2 contains a broken object level authorization (BOLA) vulnerability in the POST /build/start/:jobId and POST /build/cancel/:jobId… Mitigation only Fix from $1,9502026-06-24 HIGH 8.7 CVE-2026-56223 Capgo before 12.128.2 contains a cross-domain SSO account takeover vulnerability in the provision-user endpoint that allows attackers to merge arbitr… Mitigation only Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-12242 The AdRotate Banner Manager plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 5.17.7 via the 'banner' at… Mitigation only Fix from $1,9502026-06-24 HIGH 8.1 CVE-2025-71361 picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers… Mitigation only Fix from $1,9502026-06-24 HIGH 8.1 CVE-2025-71354 picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Atta… Mitigation only Fix from $1,9502026-06-24 HIGH 7.9 CVE-2026-10745 Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tamperi… Mitigation only Fix from $1,9502026-06-24 HIGH 8.8 CVE-2026-7761 The Ultimate Member plugin for WordPress is vulnerable to Account Takeover via Password Reset Link Disclosure in all versions up to and including 2.1… Mitigation only Fix from $1,9502026-06-24 HIGH 7.6 CVE-2026-56052 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in FunnelKit Funnel Builder by FunnelKit allows Bl… Mitigation only Fix from $1,9502026-06-24 HIGH 7.7 CVE-2026-9710 The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce ne… Mitigation only Fix from $1,9502026-06-24 HIGH 7.7 CVE-2026-9709 The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to di… Mitigation only Fix from $1,9502026-06-24 HIGH 7.2 CVE-2026-9643 The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions… Mitigation only Fix from $1,9502026-06-24 MEDIUM 6.4 CVE-2026-9620 The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-9612 The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and inc… Mitigation only Fix from $1,6002026-06-24 HIGH 7.5 CVE-2026-9179 The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in… Mitigation only Fix from $1,9502026-06-24 HIGH 7.5 CVE-2026-9178 The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the… Mitigation only Fix from $1,9502026-06-24 MEDIUM 5.3 CVE-2026-9175 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and… Mitigation only Fix from $1,6002026-06-24 MEDIUM 5.3 CVE-2026-9172 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due t… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.1 CVE-2026-8905 The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due t… Mitigation only Fix from $1,6002026-06-24 MEDIUM 6.4 CVE-2026-8896 The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such … Mitigation only Fix from $1,6002026-06-24