Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-19044

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the…

No fix yet
Fix from $1,600 2026-08-06
Apr Util HIGH 7.5
CVE-2025-49506

APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti…

Fix: 1.6.4+
Fix from $1,950 2026-08-06
Rvtools CRITICAL 9.1
CVE-2026-64993

Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c…

Fix: 4.8.1+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-5134

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C…

No fix yet
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19041

A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the f…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19040

A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Execu…

Patch available
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-18501

The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cr…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 8.3
CVE-2026-16731

OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may …

No fix yet
Fix from $1,950 2026-08-06
Unclassified HIGH 8.7
CVE-2026-16315

OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may …

No fix yet
Fix from $1,950 2026-08-06
Glassfish CRITICAL 9.6
CVE-2026-12605

In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled …

Fix: 8.0.4+
Fix from $2,300 2026-08-06
Unclassified HIGH 7.5
CVE-2026-66733

Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauth…

Patch available
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.9
CVE-2026-66732

Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections ar…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 7.5
CVE-2026-65551

Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-19039

A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of t…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.3
CVE-2026-19038

A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file s…

Patch available
Fix from $1,600 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19036

A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-0673

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via t…

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 5.4
CVE-2026-8166

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu…

No fix yet
Fix from $1,600 2026-08-06
Cxf HIGH 7.5
CVE-2026-68481

In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:tr…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-68079

In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-65583

Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-63687

Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Cxf CRITICAL 9.1
CVE-2026-61466

In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-5391

The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' …

No fix yet
Fix from $1,600 2026-08-06
Unclassified MEDIUM 6.4
CVE-2026-5158

The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '…

No fix yet
Fix from $1,600 2026-08-06
Cxf HIGH 8.1
CVE-2026-57818

A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting…

Fix: 3.6.12 / 4.1.8+
Fix from $1,950 2026-08-06
Unclassified HIGH 7.2
CVE-2026-19035

A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m…

No fix yet
Fix from $1,950 2026-08-06
Unclassified MEDIUM 5.3
CVE-2026-11983

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du…

No fix yet
Fix from $1,600 2026-08-06
Unclassified HIGH 7.2
CVE-2025-15028

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Si…

No fix yet
Fix from $1,950 2026-08-06
Cxf CRITICAL 9.8
CVE-2026-66909

Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla…

Fix: 3.6.12 / 4.1.8+
Fix from $2,300 2026-08-06