Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-12949 The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and i… No fix yet Fix from $5,7502026-08-14 HIGH 8.8 CVE-2026-19792 A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component h… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19791 A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the comp… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19790 A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the compon… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19789 A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /gofor… No fix yet Fix from $4,9002026-08-14 HIGH 8.8 CVE-2026-19788 A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of t… No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-18109 The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.… No fix yet Fix from $4,9002026-08-14 HIGH 7.2 CVE-2026-19771 A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component … No fix yet Fix from $4,9002026-08-14 MEDIUM 5.3 CVE-2026-19770 A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19767 A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimin… No fix yet Fix from $4,0002026-08-14 MEDIUM 6.3 CVE-2026-19765 A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the functio… No fix yet Fix from $4,0002026-08-14 HIGH 7.3 CVE-2026-19764 A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the fi… No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19762 A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the… No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19758 A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of… No fix yet Fix from $4,9002026-08-14 HIGH 7.3 CVE-2026-19757 A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the co… No fix yet Fix from $4,9002026-08-14 MEDIUM 6.3 CVE-2026-19756 A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the compo… No fix yet Fix from $4,0002026-08-13 HIGH 7.3 CVE-2026-19753 A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/… No fix yet Fix from $4,9002026-08-13 HIGH 8.8 CVE-2026-73841 OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.3 CVE-2026-73665 FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socke… No fix yet Fix from $5,7502026-08-13 HIGH 8.6 CVE-2026-73664 FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ… No fix yet Fix from $4,9002026-08-13 HIGH 7.7 CVE-2026-72857 Budibase before 3.40.0 fails to redact datasource credentials stored in STRING typed fields, allowing authenticated users to read MongoDB connection … No fix yet Fix from $4,9002026-08-13 HIGH 8.1 CVE-2026-72856 Budibase versions before 3.40.0 contain an authorization/authentication bypass in the PUT /api/global/users/tenant/owner (changeTenantOwnerEmail) end… No fix yet Fix from $4,9002026-08-13 HIGH 8.5 CVE-2026-72855 Budibase before 3.40.0 contains server-side request forgery vulnerabilities in OpenAPI query import and REST query execution that allow authenticated… No fix yet Fix from $4,9002026-08-13 HIGH 7.6 CVE-2026-72853 Budibase before 3.40.0 contains a SQL injection vulnerability in the Oracle datasource connector's post-write row lookup that fails to escape table n… No fix yet Fix from $4,9002026-08-13 CRITICAL 10.0 CVE-2026-72851 Budibase before 3.40.0 contains an unauthenticated SQL injection vulnerability in webhook-triggered automations with EXECUTE_QUERY steps. Attackers c… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.1 CVE-2026-72850 Budibase before 3.40.0 fails to properly sanitize S3 object keys, allowing authenticated builders to upload files with traversal sequences that are p… No fix yet Fix from $5,7502026-08-13 HIGH 7.7 CVE-2026-72849 Budibase before 3.40.0 contains a cross-site request forgery vulnerability in the chat-link handoff endpoint that allows attackers to bind an externa… No fix yet Fix from $4,9002026-08-13 CRITICAL 9.9 CVE-2026-72842 luci-app-lxc contains an ACL inconsistency vulnerability that allows low-privileged authenticated LuCI users to access backend container management r… No fix yet Fix from $5,7502026-08-13 CRITICAL 9.9 CVE-2026-72841 luci-app-openvpn fails to properly validate the instance_name2 parameter during file upload, allowing authenticated users to perform path traversal a… No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-72840 OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs/root to users intended … No fix yet Fix from $4,9002026-08-13