Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-18963 A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red… No fix yet Fix from $5,7502026-08-18 MEDIUM 5.5 CVE-2026-75485 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy object is dumped in raw form, … No fix yet Fix from $4,0002026-08-18 MEDIUM 5.5 CVE-2026-73834 A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper Custom Resources that embed … No fix yet Fix from $4,0002026-08-18 HIGH 8.9 CVE-2026-73373 Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not incl… No fix yet Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-73371 Joomla! Core - [20260808] - Improper ACL checks for batch copy actions in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthori… No fix yet Fix from $4,0002026-08-18 HIGH 8.2 CVE-2026-73337 Joomla! Core - [20260807] - MFA Authentication Bypass in Joomla 4.0.0-5.4.7 and 6.0.0-6.1.2 - Insufficient state checks lead to a vector that allows … No fix yet Fix from $4,9002026-08-18 MEDIUM 5.1 CVE-2026-72532 Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow… No fix yet Fix from $4,0002026-08-18 HIGH 8.5 CVE-2026-71574 Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a… No fix yet Fix from $4,9002026-08-18 HIGH 7.7 CVE-2026-71365 A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.3 CVE-2026-45118 MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in… No fix yet Fix from $5,7502026-08-18 HIGH 8.7 CVE-2026-45115 MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to… No fix yet Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-19500 The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or sub… No fix yet Fix from $4,9002026-08-18 CRITICAL 9.6 CVE-2026-12564 A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r… No fix yet Fix from $5,7502026-08-18 CRITICAL 10.0 CVE-2026-75784 A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx … No fix yet Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile … No fix yet Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-74015 Unauthenticated SQL Injection in Readabler < 2.0.18 versions. No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-74012 Editor PHP Object Injection in TaxoPress <= 3.51.0 versions. No fix yet Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-74009 Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-74008 Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-74007 Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-74004 Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions. No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73997 Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-73996 Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. No fix yet Fix from $5,7502026-08-18 MEDIUM 5.4 CVE-2026-73995 Subscriber Broken Authentication in User Registration <= 5.2.6 versions. No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73994 Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. No fix yet Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73404 Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. No fix yet Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-73400 Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. No fix yet Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73399 Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 6.5 CVE-2026-73398 Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions. No fix yet Fix from $4,0002026-08-18 CRITICAL 9.8 CVE-2026-73397 Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions. No fix yet Fix from $5,7502026-08-18