Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's …

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-65310

ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any a…

No fix yet
Fix from $1,950 2026-07-31
Build Of Keycloak MEDIUM 5.4
CVE-2026-18218

A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-65309

ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way passw…

No fix yet
Fix from $1,950 2026-07-31
Build Of Keycloak MEDIUM 5.4
CVE-2026-18211

A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak HIGH 8.1
CVE-2026-18215

Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove…

No fix yet
Fix from $1,950 2026-07-31
Build Of Keycloak HIGH 8.1
CVE-2026-18214

Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo…

No fix yet
Fix from $1,950 2026-07-31
Build Of Keycloak MEDIUM 6.5
CVE-2026-18208

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme…

No fix yet
Fix from $1,600 2026-07-31
Build Of Keycloak MEDIUM 6.5
CVE-2026-18203

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.4
CVE-2026-8155

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated …

No fix yet
Fix from $1,600 2026-07-31
Unclassified CRITICAL 10.0
CVE-2026-18452

DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed AP…

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 8.8
CVE-2026-16236

The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing …

Mitigation only
Fix from $1,950 2026-07-31
Unclassified HIGH 8.1
CVE-2026-15258

The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-15048

The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to re…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14931

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capabi…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14930

The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allo…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14928

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.1
CVE-2026-14922

WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (do…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.1
CVE-2026-14921

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(),

No fix yet
Fix from $1,600 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-14919

The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check t…

No fix yet
Fix from $2,300 2026-07-31
Unclassified MEDIUM 6.1
CVE-2026-14845

The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and …

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-14843

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un…

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14834

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers …

No fix yet
Fix from $1,600 2026-07-31
Unclassified MEDIUM 6.8
CVE-2026-14833

The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image light…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14830

The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the asso…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-14554

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing use…

No fix yet
Fix from $1,600 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-14483

The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5…

Mitigation only
Fix from $2,300 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14333

The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-14319

The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing…

No fix yet
Fix from $1,950 2026-07-31