Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-16810

The Bit Form – Contact Form, Payment Forms, Multi Step Forms, Calculator & Custom Form Builder plugin for WordPress is vulnerable to generic SQL Inje…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 5.9
CVE-2026-16739

The Epeken All Kurir for Woocommerce WordPress plugin through 2.1.2 does not verify that a payment-confirmation request originates from the owner of …

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 8.6
CVE-2026-15205

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before using it in a SQL query withi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputting it inside an HTML attribut…

No fix yet
Fix from $4,000 2026-08-14
Unclassified CRITICAL 9.8
CVE-2026-12949

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and i…

No fix yet
Fix from $5,750 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19792

A security flaw has been discovered in Tenda G0 up to 20260625. Impacted is the function setPortMapping of the file /goform/module of the component h…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19791

A weakness has been identified in Tenda G0 up to 20260625. The affected element is the function addStaticRoute of the file /goform/module of the comp…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19790

A vulnerability was identified in Tenda G0 up to 20260625. This issue affects the function formSetPortMirror of the file /goform/module of the compon…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19789

A vulnerability was determined in Tenda AC1206 15.03.06.23_multi_TD01. This vulnerability affects the function set_wl_guest_iplist of the file /gofor…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 8.8
CVE-2026-19788

A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01. This affects the function set_device_name of the file /goform/SetOnlineDevName of t…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19785

A vulnerability has been found in francoisjacquet RosarioSIS up to 12.7.4. This vulnerability affects unknown code of the file modules/Students/inclu…

Patch available
Fix from $4,000 2026-08-14
Unclassified HIGH 7.2
CVE-2026-18109

The W3 Total Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment Author Name in all versions up to, and including, 2.…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.2
CVE-2026-19771

A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component …

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 5.3
CVE-2026-19770

A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affected by this vulnerability is the function downloadReport of the file src/smadex-…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19767

A weakness has been identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file viewdoctortimin…

No fix yet
Fix from $4,000 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19765

A security flaw has been discovered in eyaushev swagger-testcase-mcp 5babb27c951fb404bc2b25ec80593616e49054e5. This vulnerability affects the functio…

No fix yet
Fix from $4,000 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19764

A vulnerability was identified in Raisecom Communication Command and Dispatch Management Platform up to 7.6.5. This affects an unknown part of the fi…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19762

A vulnerability was found in DTStack Taier 1.4.0. Affected by this vulnerability is the function Paths.ge of the file FileChunkController.java of the…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19758

A vulnerability was determined in dromara lamp-cloud up to 5.10.0. This issue affects some unknown processing of the file FileChunkController.java of…

No fix yet
Fix from $4,900 2026-08-14
Unclassified HIGH 7.3
CVE-2026-19757

A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vulnerability affects unknown code of the file FileAnyoneController.java of the co…

No fix yet
Fix from $4,900 2026-08-14
Unclassified MEDIUM 6.3
CVE-2026-19756

A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. This affects an unknown part of the file DefGenProjectController.java of the compo…

No fix yet
Fix from $4,000 2026-08-13
Unclassified HIGH 7.3
CVE-2026-19753

A vulnerability was detected in Model Context Protocol mcp-rdf-explorer 1.0.0. Affected is the function explore_url of the file src/mcp-rdf-explorer/…

No fix yet
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.6
CVE-2026-73843

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.2 and 1.1.2, internal/cluster-gateway/server.go served caller-f…

Patch available
Fix from $5,750 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73842

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, internal/cluster-gateway/server.go ex…

Patch available
Fix from $5,750 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73841

OpenChoreo is a complete, open-source developer platform for Kubernetes. From 1.2.0-rc.1 until 1.2.0, internal/openchoreo-api/api/handlers/exec.go an…

No fix yet
Fix from $4,900 2026-08-13
Unclassified MEDIUM 5.3
CVE-2026-73840

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.3, 1.1.3, and 1.2.0-rc.2, the POST /api/v1alpha1/autobuild endp…

Patch available
Fix from $4,000 2026-08-13
Unclassified HIGH 8.8
CVE-2026-73667

OpenChoreo is a complete, open-source developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.0-rc.2, OpenChoreo Workflow Plane templates u…

Patch available
Fix from $4,900 2026-08-13
Unclassified HIGH 8.2
CVE-2026-73666

OpenChoreo is a developer platform for Kubernetes. Prior to 1.0.4, 1.1.4, and 1.2.1, the OpenChoreo Backstage backend hardcoded backend.auth.dangerou…

Patch available
Fix from $4,900 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-73665

FreePBX is an open source IP PBX. Prior to 17.0.9, the UCP Node server on ports 8001 and 8003 uses io.use(checkAuth) in node/lib/server.js, but Socke…

No fix yet
Fix from $5,750 2026-08-13
Unclassified HIGH 8.6
CVE-2026-73664

FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administ…

No fix yet
Fix from $4,900 2026-08-13