Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-73385

Unauthenticated Broken Access Control in Outranking Plugin Options <= 1.1.3 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 7.5
CVE-2026-73384

Unauthenticated Sensitive Data Exposure in Pay with Contact Form 7 <= 1.0.4 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73364

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

Fix unknown
Fix from $5,750 2026-08-19
Unclassified MEDIUM 6.5
CVE-2026-73363

Unauthenticated Broken Access Control in Taxi Booking Manager for WooCommerce < 2.0.8 versions.

Fix unknown
Fix from $4,000 2026-08-19
Unclassified HIGH 7.1
CVE-2026-73354

Unauthenticated Cross Site Scripting (XSS) in SimplyRETS Real Estate IDX <= 3.2.8 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73347

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

Fix unknown
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

Fix unknown
Fix from $5,750 2026-08-19
Unclassified HIGH 7.1
CVE-2026-73184

Unauthenticated Cross Site Scripting (XSS) in Global Gallery <= 11.1.2 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

Fix unknown
Fix from $5,750 2026-08-19
Unclassified HIGH 7.1
CVE-2026-73182

Unauthenticated Cross Site Scripting (XSS) in BBQ Pro <= 3.9 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI…

Fix unknown
Fix from $5,750 2026-08-19
Unclassified HIGH 7.7
CVE-2026-67363

Joomla Extension - balbooa.com - Pre-auth Payment Amount Tampering in Balbooa Forms < 2.4.3.2 - The stripeCharges and payAuthorize endpoints accept t…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 8.5
CVE-2026-66668

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-66613

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

Fix unknown
Fix from $5,750 2026-08-19
Unclassified HIGH 7.1
CVE-2026-66596

Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 7.1
CVE-2026-61986

Unauthenticated Cross Site Scripting (XSS) in Contest Gallery <= 30.0.5 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 8.5
CVE-2026-32552

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

Fix unknown
Fix from $4,900 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…

Fix unknown
Fix from $5,750 2026-08-19
Unclassified HIGH 8.8
CVE-2026-19489

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified MEDIUM 5.1
CVE-2026-18371

HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to o…

Fix unknown
Fix from $4,000 2026-08-19
Unclassified MEDIUM 5.7
CVE-2026-16440

In Eclipse OpenJ9 versions up to 0.60, a crafted .class file with deeply nested annotations causes a segmentation fault.

Fix unknown
Fix from $4,000 2026-08-19
Unclassified HIGH 7.1
CVE-2026-76164

AIL Framework contains a server-side request forgery (SSRF) vulnerability in its crawler submission functionality. A low-privileged authenticated use…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.1
CVE-2026-75900

An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_CheckHeader() function. The entry guard checks the buffer length against sizeof(…

Fix unknown
Fix from $4,000 2026-08-19
Unclassified HIGH 7.4
CVE-2026-58088

The ELF core dump code counted the number of dumpable VM map entries, allocated a buffer for the corresponding program headers, then iterated over th…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 7.8
CVE-2026-58087

The GETALL and SETALL commands in semctl(2) recorded the number of semaphores in the target set, dropped the lock protecting the set, allocated a buf…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 8.4
CVE-2026-58083

While the kernel was copying knotes during fork, a knote with a timer-based filter could fire and be enqueued on the kqueue's active list before the …

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 7.2
CVE-2026-75981

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to unauthenticated Stored Cross-Site Scripti…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified HIGH 7.2
CVE-2026-15780

The WP Statistics – Simple, privacy-friendly Google Analytics alternative plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '…

Fix unknown
Fix from $4,900 2026-08-19
Unclassified MEDIUM 6.4
CVE-2026-15446

The EWWW Image Optimizer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'data-script' Lazy Load Attribute in Post Content in a…

Fix unknown
Fix from $4,000 2026-08-19
Unclassified MEDIUM 6.9
CVE-2026-8810

On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.

Fix unknown
Fix from $4,000 2026-08-19