Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-14557

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-ver…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified MEDIUM 6.5
CVE-2026-15254

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrative appointment-listing short…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 6.1
CVE-2026-13340

The SVG Support WordPress plugin before 2.5.17 does not apply its SVG sanitisation to uploaded files using the .svgz extension, even though it regist…

No fix yet
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-12965

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, a…

No fix yet
Fix from $2,300 2026-08-03
Unclassified HIGH 8.1
CVE-2025-15672

The ChamaWP WordPress plugin before 1.0.13 does not properly validate user input before passing it to a PHP deserialization function, allowing unaut…

No fix yet
Fix from $1,950 2026-08-03
Enterprise Linux MEDIUM 5.5
CVE-2026-6695

A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image f…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.5
CVE-2026-6694

A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) imag…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.4
CVE-2026-18584

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impacted is an unknown function of …

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-18583

A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAccess of the file src/iec61850/…

Patch available
Fix from $1,600 2026-08-03
Unclassified HIGH 8.7
CVE-2026-14682

In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up-front allocation on a definite-length read. This issue also affects Bouncy Cast…

Patch available
Fix from $1,950 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-13586

In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption KDF iteration-count bound (DoS). This issue also affects Bouncy Castle for Java…

Patch available
Fix from $1,600 2026-08-03
Unclassified HIGH 8.7
CVE-2026-13506

In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing resets nesting-depth guard. This issue also affects Bouncy Castle for Java LTS bef…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12860

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issue also affects Bouncy Castle …

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12852

In Bouncy Castle for Java before 1.85, MLS wire decoder allocates attacker-declared opaque length before bounds check.

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12817

In Bouncy Castle for Java before 1.85, OpenPGP AEAD decryption skips final tag on chunk-aligned data. This issue also affects Bouncy Castle for Java …

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12816

In Bouncy Castle for Java before 1.85, IESEngine stream-mode MAC forgery via length-dependent KDF split. This issue also affects Bouncy Castle for Ja…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12803

In Bouncy Castle for Java before 1.85, KCCMBlockCipher MAC does not bind nonce when AAD is absent (cross-nonce AEAD forgery). This issue also affects…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-12802

In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fails to enforce tag-length on decryption. This issue also affects Bouncy Castle for Jav…

Patch available
Fix from $1,950 2026-08-03
Mt6991 Firmware MEDIUM 6.0
CVE-2026-20498

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a ma…

No fix yet
Fix from $1,600 2026-08-03
Unclassified MEDIUM 5.3
CVE-2026-58063

In Bouncy Castle for Java before 1.85, BCFKS keystore load honours unbounded KDF cost from untrusted file. This issue also affects Bouncy Castle for …

Patch available
Fix from $1,600 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-58062

In Bouncy Castle for Java before 1.85, Stapled OCSP response accepted without binding to the checked certificate. This issue also affects Bouncy Cast…

Patch available
Fix from $2,300 2026-08-03
Unclassified HIGH 8.7
CVE-2026-58061

In Bouncy Castle for Java before 1.85, CCM-family modes write plaintext to caller buffer before tag check. This issue also affects Bouncy Castle for …

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-58060

In Bouncy Castle for Java before 1.85, HSS public-key level count unbounded, enabling huge allocation on verify. This issue also affects Bouncy Castl…

Patch available
Fix from $1,950 2026-08-03
Unclassified HIGH 8.7
CVE-2026-58059

In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy Castle for…

Patch available
Fix from $1,950 2026-08-03
Mt7925 Firmware HIGH 7.8
CVE-2026-20495

In Bluetooth driver, there is a possible permission bypass due to a missing permission check. This could lead to local escalation of privilege with U…

No fix yet
Fix from $1,950 2026-08-03
Mt6989 Firmware MEDIUM 6.0
CVE-2026-20497

In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious …

No fix yet
Fix from $1,600 2026-08-03
Mt6890 Firmware MEDIUM 5.5
CVE-2026-20494

In wifi, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure if a malicious actor h…

No fix yet
Fix from $1,600 2026-08-03
Mt6990 Firmware MEDIUM 5.5
CVE-2026-20492

In Audio HAL, there is a possible system becoming unresponsive due to a race condition. This could lead to local denial of service with User executio…

No fix yet
Fix from $1,600 2026-08-03
Mt2735 Firmware MEDIUM 5.5
CVE-2026-20491

In med, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local denial of service with User execution priv…

No fix yet
Fix from $1,600 2026-08-03
Mt8910 Firmware MEDIUM 6.7
CVE-2026-20486

In imgsensor, there is a possible application crash due to incorrect error handling. This could lead to local escalation of privilege if a malicious …

No fix yet
Fix from $1,600 2026-08-03