Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.8
CVE-2026-64570

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix fils_discovery double free on alloc failure ieee80211_set_f…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.8
CVE-2026-64568

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: fix unsol_bcast_probe_resp double free on alloc failure ieee802…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.8
CVE-2026-64567

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 f…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-64566

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_sk…

No fix yet
Fix from $2,300 2026-08-05
Lucy HIGH 7.5
CVE-2026-61483

** UNSUPPORTED WHEN ASSIGNED ** Uncontrolled Recursion vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this project …

No fix yet
Fix from $1,950 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61486

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro…

No fix yet
Fix from $2,300 2026-08-05
Lucy HIGH 7.5
CVE-2026-61485

** UNSUPPORTED WHEN ASSIGNED ** Memory Allocation with Excessive Size Value vulnerability in Apache Lucy. This issue affects Apache Lucy: all versio…

No fix yet
Fix from $1,950 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-5581

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.5
CVE-2026-59675

When API audit logging is enabled, the middleware reads the entire HTTP request body into memory without enforcing a size limit on login endpoints. B…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-55998

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid cluster ID references a clust…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-55997

Rancher issues long-lived registration tokens to authenticate nodes and agents joining a downstream cluster. These tokens were stored and exposed in …

Mitigation only
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.8
CVE-2026-55747

The pocketflow-coding-agent cookbook example in The-Pocket/PocketFlow implements a helper as a thin os.path.join(workdir, p) wrapper with no canonica…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.3
CVE-2026-55739

Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->compan…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.1
CVE-2026-54418

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-54416

Pluck CMS through 4.7.21 restricts dangerous file uploads in its admin file-management feature using a fixed blacklist in data/inc/files.php ('.php',…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-4431

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_pos…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 7.5
CVE-2026-18881

The TableOn – WordPress Posts Table Filterable plugin for WordPress is vulnerable to blind SQL Injection via the `filter_data[comment_count]` paramet…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-17532

The Seraphinite Accelerator plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'seraph_accel_prep' parameter in versions up…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-17505

The Translate Multilingual sites – TranslatePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in versi…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-15281

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the wp_ajax_save-attachment-compat…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-12000

The Page and Post Restriction plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 1.4.0 via the Word…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-11977

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to generic SQL Injection via the…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-11454

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up…

No fix yet
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68077

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading…

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache …

Fix: 10.1.0+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.0
CVE-2026-71201

In OpenStack Ironic through 38.0.0, a project reader that makes a crafted request to Ironic can return Portgroups assigned to Nodes owned or leased b…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70375

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the Git deployer component. GitDeployer.pullRepo in src/Server…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70374

HashBrown CMS through 1.4.6 contains an OS Command Injection vulnerability (CWE-78) in the media upload thumbnail generation routine. Media.generateT…

No fix yet
Fix from $1,950 2026-08-05
Qpid Broker J MEDIUM 6.5
CVE-2026-68080

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated attacker to cause excessive resou…

Fix: 10.1.0+
Fix from $1,600 2026-08-05