Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.3
CVE-2026-14317

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by the administrator, deriving it…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.8
CVE-2026-13609

The Frontend Admin by DynamiApps WordPress plugin before 3.29.9 decodes HTML entities in a submitted form field value after sanitizing it, which rest…

Mitigation only
Fix from $1,950 2026-07-31
Unclassified HIGH 7.2
CVE-2026-13392

The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a user with administrative cap…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 8.6
CVE-2026-12721

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before using it in a SQL statement, al…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-12720

The Kirki WordPress plugin before 6.0.13 does not restrict which classes may be instantiated when it deserialises data that unauthenticated users ca…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 5.4
CVE-2026-12697

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting user before deleting its messag…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 8.1
CVE-2026-12695

The miniOrange 2FA WordPress plugin before 6.2.6 does not validate the submitted one-time password against the targeted user's stored secret, instea…

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 8.1
CVE-2026-12251

The Ultimate Member WordPress plugin before 2.12.1 does not filter administrator-level capabilities from the roles it makes selectable on its regist…

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-63223

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, the is_image and mime_in upload validation rules do not independently enforce a safe c…

Patch available
Fix from $2,300 2026-07-31
Unclassified HIGH 7.5
CVE-2026-63222

CodeIgniter is a PHP full-stack web framework. Prior to 4.7.4, calling UploadedFile::move() without a second argument uses the client-provided filena…

Patch available
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.4
CVE-2026-63221

CodeIgniter is a PHP full-stack web framework. From 4.3.0 through 4.7.3, Query Builder deleteBatch() substitutes bound values from where() conditions…

Patch available
Fix from $2,300 2026-07-31
Unclassified HIGH 7.5
CVE-2026-56673

ComfyUI is a modular diffusion model GUI, API, and backend with a graph-and-node interface. Prior to 0.28.0, folder_paths.get_annotated_filepath and …

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.2
CVE-2026-56672

ComfyUI is a node-based diffusion model GUI, API, and backend. Prior to 0.28.0, GET /userdata/{file} served user-controlled HTML and SVG files with e…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-56671

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, get_model_preview in app/model_manager.py jo…

Patch available
Fix from $1,950 2026-07-31
Unclassified HIGH 8.2
CVE-2026-56670

ComfyUI is a modular diffusion model GUI, api and backend with a graph/nodes interface. Prior to 0.28.0, the /view endpoint served uploaded SVG files…

Patch available
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.3
CVE-2026-62323

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, ViewerSessionValidation uses only the session-id prefix of a WOPI acc…

Patch available
Fix from $1,600 2026-07-31
Unclassified HIGH 7.1
CVE-2026-55502

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, POST /api/v4/admin/policy/oauth/signin requires only Admin.Read even …

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.5
CVE-2026-55497

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image decoders limit compressed fil…

Patch available
Fix from $1,600 2026-07-31
Unclassified MEDIUM 5.3
CVE-2026-43833

Full details and mitigation steps are currently restricted and will be published at a later date.

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.5
CVE-2026-43832

Full details and mitigation steps are currently restricted and will be published at a later date.

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.5
CVE-2026-43831

Full details and mitigation steps are currently restricted and will be published at a later date.

No fix yet
Fix from $1,950 2026-07-31
Unclassified CRITICAL 9.8
CVE-2026-43830

Full details and mitigation steps are currently restricted and will be published at a later date.

No fix yet
Fix from $2,300 2026-07-31
Unclassified HIGH 7.5
CVE-2026-43829

Full details and mitigation steps are currently restricted and will be published at a later date.

No fix yet
Fix from $1,950 2026-07-31
Unclassified HIGH 7.1
CVE-2026-6890

A use of default credentials vulnerability in the Advantech ECU-1251D allows a remote attacker to gain unauthorised access to the device via SSH usin…

No fix yet
Fix from $1,950 2026-07-31
Unclassified MEDIUM 6.9
CVE-2026-6889

A denial of service vulnerability in the Advantech ECU-1251D allows a network-adjacent attacker to send a DNP3 signal to the Digital Output address o…

No fix yet
Fix from $1,600 2026-07-31
Unclassified HIGH 7.8
CVE-2026-18157

A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnera…

Patch available
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases HIGH 7.5
CVE-2026-14541

An authentication bypass and audience confusion vulnerability exists in the Google OAuth provider component of Google mcp-toolbox version 1.4.0. When…

Patch available
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases MEDIUM 6.1
CVE-2026-14540

A Server-Side Request Forgery (SSRF) vulnerability exists in the generic HTTP source and tool components of Google mcp-toolbox versions 0.3.0 through…

Fix: 1.5.0+
Fix from $1,600 2026-07-31
Mcp Toolbox For Databases HIGH 7.5
CVE-2026-14539

An allocation of resources without limits vulnerability in the HTTP handler component of Google mcp-toolbox versions up to and including 1.4.0 allows…

Fix: 1.5.0+
Fix from $1,950 2026-07-31
Mcp Toolbox For Databases HIGH 7.7
CVE-2026-14538

An improper authorization and security-boundary bypass vulnerability in the bigquery-execute-sql tool component of Google mcp-toolbox versions 0.16.1…

Fix: after 1.4.0
Fix from $1,950 2026-07-31