Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-61982

Unauthenticated Cross Site Scripting (XSS) in SiteGuard WP Plugin <= 1.8.6 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-61964

Unauthenticated Cross Site Scripting (XSS) in Ninja Tables <= 5.2.9 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-61963

Unauthenticated Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.38 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-61961

Unauthenticated Cross Site Scripting (XSS) in EmbedPress <= 4.5.6 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-61959

Subscriber Cross Site Scripting (XSS) in Business Directory <= 6.4.24 versions.

No fix yet
Fix from $1,600 2026-08-06
Virtual Storage Integrator CRITICAL 9.8
CVE-2026-54489

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) a Sensitive Information Disclosure vulnerability. …

Fix: 10.11.1.0+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-53976

OpenChamber 1.11.7 contains a path traversal vulnerability in the file-serving endpoints /api/fs/read, /api/fs/stat, and /api/fs/raw that allows unau…

Patch available
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-53975

OpenChamber 1.11.7 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary shell commands b…

Patch available
Fix from $2,300 2026-08-06
Apr Util HIGH 7.5
CVE-2026-34502

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility memcached client This issue affects Apache Portable Runtime Utility: fro…

Fix: after 1.6.3
Fix from $1,950 2026-08-06
Apr Util HIGH 7.5
CVE-2026-34501

Heap-based Buffer Overflow vulnerability in Apache Portable Runtime Utility redis client. This issue affects Apache Portable Runtime Utility: from 1…

Fix: 1.6.4+
Fix from $1,950 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-34191

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache Portable Runtime Utility via apr_dbd_ora…

Fix: after 1.6.3
Fix from $2,300 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-32548

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-32469

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Apr Util CRITICAL 9.1
CVE-2026-32327

A bug in APR-util version 1.6.3 (and earlier) allows a stack recursion attack against any library consumer which parses XML from untrusted sources an…

Fix: 1.6.4+
Fix from $2,300 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-28180

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.9
CVE-2026-28179

Shop manager Cross Site Scripting (XSS) in FiboSearch <= 1.33.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-28178

Contributor Cross Site Scripting (XSS) in Powerkit <= 3.1.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28177

Unauthenticated Cross Site Scripting (XSS) in Popup Maker <= 1.23.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28172

Unauthenticated Cross Site Request Forgery (CSRF) in Tracking Code Manager <= 2.6.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-28169

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-28146

Contributor Arbitrary File Download in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.14 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28143

Unauthenticated Cross Site Scripting (XSS) in Forminator <= 1.56.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28141

Unauthenticated Cross Site Scripting (XSS) in NextGEN Gallery <= 4.2.3 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.5
CVE-2026-28140

Unauthenticated Broken Access Control in JetFormBuilder <= 3.6.4.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28139

Unauthenticated PHP Object Injection in Ajax Search Lite <= 4.14.4 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified HIGH 8.8
CVE-2026-28111

Contributor Privilege Escalation in Forminator <= 1.56.0 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 7.1
CVE-2026-28082

Unauthenticated Cross Site Scripting (XSS) in JetEngine <= 3.8.13.1 versions.

No fix yet
Fix from $1,950 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-28005

Unauthenticated Privilege Escalation in Kadence WooCommerce Email Designer <= 1.5.19 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.5
CVE-2026-25403

Unauthenticated Broken Access Control in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19045

A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog.showSecretDialog of the file…

No fix yet
Fix from $1,600 2026-08-06