Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-18753

The product firmware contains an embedded, static RSA private key utilized by the Lighttpd web server for TLS termination. Exposure of this private k…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-64564

In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_a…

No fix yet
Fix from $2,300 2026-08-04
Unclassified HIGH 7.8
CVE-2026-64563

In the Linux kernel, the following vulnerability has been resolved: rhashtable: clear stale iter->p on table restart rhashtable_walk_start_check() …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-64562

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow …

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.8
CVE-2026-64561

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Ch…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 8.0
CVE-2026-16623

The Create Block WordPress plugin before 2.10.0 does not correctly escape user-supplied text before writing it into a generated PHP pattern file, al…

No fix yet
Fix from $1,950 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-16618

The Improve SEO WordPress plugin through 2.0.11 does not properly validate uploaded files, checking only the file content type while writing the file…

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-16548

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin before 1.8.2 does not validate …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-16547

The REST API Log WordPress plugin before 1.7.1 does not bind the token protecting its log download feature to the log entry being requested, nor does…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-16536

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL before performing a server-side …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-16293

The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11.16.11 does not sanitise and escape some of its Podcast Episode settings, which…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-16069

The Brizy WordPress plugin before 2.8.19 does not sanitize or escape featured-image focal-point coordinates submitted through one of its AJAX action…

No fix yet
Fix from $1,600 2026-08-04
Unclassified CRITICAL 9.3
CVE-2026-15958

The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions …

No fix yet
Fix from $2,300 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-14939

The Visualizer WordPress plugin before 4.0.6 does not restrict a user-supplied URL to safe address ranges before fetching it server-side, allowing u…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.8
CVE-2026-14872

The Database for Contact Form 7, WPforms, Elementor forms WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before usin…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.4
CVE-2026-14848

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified through its change-subscription…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-14816

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of the data subject when recording…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.8
CVE-2026-10526

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests through unauthenticated endpoin…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 8.7
CVE-2026-16881

A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component does not adequately validate…

No fix yet
Fix from $1,950 2026-08-04
Unclassified HIGH 7.3
CVE-2026-42169

A heap-buffer-overflow vulnerability exists in the APNG (Animated PNG) file loader of GIMP. This flaw occurs when the `fcTL` width exceeds the `IHDR`…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18723

A vulnerability was determined in diaowen DWSurvey up to 6.14.0. The affected element is an unknown function of the file /api/dwsurvey/app/survey/up-…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18722

A vulnerability was found in diaowen DWSurvey up to 6.14.0. Impacted is the function in DwDeisgnSurveyController.devSurvey. of the file /api/dwsurvey…

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.2
CVE-2026-14818

A path traversal vulnerability in the CLI command used to execute configuration files in Zyxel ATP series firmware versions from V4.32 through V5.42 …

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 6.5
CVE-2026-8508

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow …

No fix yet
Fix from $1,600 2026-08-04
Unclassified HIGH 7.2
CVE-2026-6837

A post-authentication command injection vulnerability in the "export-cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could…

No fix yet
Fix from $1,950 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-18720

A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?plugin/msgWarning/action of t…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.3
CVE-2026-18719

A vulnerability was detected in cemtan sar2html 4.0.0. This affects an unknown part of the file sar2html.py of the component Search. Performing a man…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 6.2
CVE-2026-58045

A flaw in Node.js allows a spoofed `TypedArray` `byteLength` to trigger a reachable assertion in the synchronous `node:zlib` APIs, causing the entire…

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.9
CVE-2026-58042

A flaw in Node.js can cause dns.resolveAny() Aborts the Node.js Process When a DNS Response Contains More Than 256 A Records. Repeated triggering …

No fix yet
Fix from $1,600 2026-08-04
Unclassified MEDIUM 5.3
CVE-2026-58041

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to continue executing a cached prepa…

No fix yet
Fix from $1,600 2026-08-04