Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 8.1
CVE-2026-15230

The YayPricing WordPress plugin before 3.5.7 does not perform capability checks on several of its REST API routes, relying only on a shared nonce, a…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-15210

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate…

No fix yet
Fix from $2,300 2026-08-05
Unclassified HIGH 8.1
CVE-2026-14553

The zportals WordPress plugin before 6.3.4 does not properly validate uploaded files, trusting the client-supplied content type and preserving the or…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.3
CVE-2026-9273

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading t…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified MEDIUM 6.1
CVE-2026-8790

The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in a…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.8
CVE-2026-8761

The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorizat…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-7753

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing capability check on the `cos…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.0
CVE-2026-71192

In OpenStack Swift through 2.38.0, the S3API middleware does not sanitize Swift-native control headers (X-Copy-From, X-Copy-From-Account) from S3 API…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.0
CVE-2026-71191

In OpenStack Swift through 2.38.0, S3API middleware does not enforce that semantic x-amz-* headers are covered by the SigV4 signature on presigned UR…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.7
CVE-2026-71190

In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic backtracking (ReDoS…

No fix yet
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68074

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Broker J HIGH 7.5
CVE-2026-68060

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 10.1.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67589

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Protonj2 HIGH 7.5
CVE-2026-67588

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.2.0+
Fix from $1,950 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67551

pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This issue…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Proton Dotnet HIGH 7.5
CVE-2026-67465

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 1.1.0+
Fix from $1,950 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66273

A pre-authentication attacker could leverage type size/count handling to cause excessive allocation leading to potential denial of service. This iss…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Qpid Proton J HIGH 7.5
CVE-2026-66257

A pre-authentication attacker could leverage unbounded symbol value caching to cause resource exhaustion leading to denial of service. This issue af…

Fix: 0.35.0+
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.7
CVE-2026-66839

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticat…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.7
CVE-2026-66344

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authentica…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.1
CVE-2026-55707

In OpenStack Neutron before 28.0.2, the subnetpool onboarding API does not verify ownership of the target subnets. An authenticated user can onboard …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-18902

A vulnerability was detected in H3C NX15 V100R017. Affected by this vulnerability is the function esps.wan.repeater.set/repeaterproc of the file /api…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-18322

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.12.0. This is due to …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-16143

The VikRentItems – Flexible Rental Management System plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the customer email field o…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-15941

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches from the WordPress dashboard. …

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.5
CVE-2026-15918

VikAppointments Service Booking Calendar wordpress plugin is vulnerable to unauthenticated SQL injection due to one of the parameters that controls h…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-11421

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Injection via the 'erpadvancefilt…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-18901

A security vulnerability has been detected in H3C NX15 V100R017. Affected is the function service.add of the file /api/esps of the component Web API.…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.2
CVE-2026-18900

A weakness has been identified in H3C NX15 V100R017. This impacts the function file.exec of the file /api/esps of the component Backend RPC. This man…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-18898

A security flaw has been discovered in UTT HiPER 1200GW up to v2.5.3-170306. This affects the function strcpy of the file /goform/ConfigAdvideo. The …

No fix yet
Fix from $1,950 2026-08-05