Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-16578

The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability che…

No fix yet
Fix from $1,950 2026-08-08
Unclassified MEDIUM 6.5
CVE-2026-16562

The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only o…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.4
CVE-2026-16558

The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and do…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 6.1
CVE-2026-16535

The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthentic…

No fix yet
Fix from $1,600 2026-08-08
Unclassified MEDIUM 5.3
CVE-2026-16282

The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured ser…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.1
CVE-2026-16267

The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, al…

No fix yet
Fix from $1,950 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-14526

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du…

No fix yet
Fix from $2,300 2026-08-08
Unclassified MEDIUM 6.4
CVE-2026-18988

The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, a…

No fix yet
Fix from $1,600 2026-08-08
Unclassified HIGH 8.7
CVE-2026-13505

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material …

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 8.7
CVE-2026-8798

In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions …

No fix yet
Fix from $1,950 2026-08-08
Unclassified HIGH 7.5
CVE-2026-52880

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-52879

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a …

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-52878

Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered …

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.9
CVE-2026-49343

Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a …

No fix yet
Fix from $1,600 2026-08-07
Unclassified MEDIUM 5.4
CVE-2026-48122

Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to v…

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 8.6
CVE-2026-48120

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup…

Patch available
Fix from $1,950 2026-08-07
Unclassified MEDIUM 5.9
CVE-2026-48047

XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, an…

Patch available
Fix from $1,600 2026-08-07
Unclassified HIGH 8.7
CVE-2026-48026

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.8…

No fix yet
Fix from $1,950 2026-08-07
Unclassified HIGH 7.5
CVE-2026-47249

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-…

No fix yet
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.5
CVE-2026-47127

Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/sub…

Patch available
Fix from $1,600 2026-08-07
Unclassified CRITICAL 9.6
CVE-2026-46409

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…

No fix yet
Fix from $2,300 2026-08-07
Unclassified MEDIUM 5.7
CVE-2026-64676

Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the …

No fix yet
Fix from $1,600 2026-08-07
Unclassified HIGH 7.1
CVE-2026-58262

Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits o…

Patch available
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.1
CVE-2026-48170

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value`…

Patch available
Fix from $2,300 2026-08-07
Unclassified HIGH 8.8
CVE-2026-48169

PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo…

No fix yet
Fix from $1,950 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-47243

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

No fix yet
Fix from $2,300 2026-08-07
Unclassified MEDIUM 5.3
CVE-2026-46405

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, o…

Patch available
Fix from $1,600 2026-08-07
Unclassified HIGH 7.1
CVE-2026-45808

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A t…

Patch available
Fix from $1,950 2026-08-07
Unclassified MEDIUM 6.6
CVE-2026-11743

The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths wi…

Patch available
Fix from $1,600 2026-08-07
Unclassified MEDIUM 6.8
CVE-2026-9031

An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by …

No fix yet
Fix from $1,600 2026-08-07