Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Data Master HIGH 8.1
CVE-2026-67245

A path traversal vulnerability was found in the VPN Clients on the ADM. The vulnerability occurs because user-controlled certificate name input is no…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Unclassified HIGH 7.5
CVE-2026-1360

The BuddyPress plugin for WordPress is vulnerable to Deserialization of Untrusted Data in all versions up to, and including, 14.5.0 This is due to th…

No fix yet
Fix from $1,950 2026-07-30
Unclassified CRITICAL 9.8
CVE-2026-16610

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via…

No fix yet
Fix from $2,300 2026-07-30
Unclassified HIGH 8.8
CVE-2026-14356

The FleekDash V2 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2.2. This is due to the plugin …

Mitigation only
Fix from $1,950 2026-07-30
Data Master HIGH 7.2
CVE-2026-67244

A format string vulnerability was found in the Notification OAuth settings of ADM. The vulnerability occurs because user-controlled notification conf…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Campaign CRITICAL 9.8
CVE-2026-48449

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

Fix: after 7.4.2
Fix from $2,300 2026-07-30
Campaign HIGH 8.6
CVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

Fix: after 7.4.2
Fix from $1,950 2026-07-30
Unclassified MEDIUM 5.3
CVE-2026-1982

The Persian Elementor (المنتور فارسی) plugin for WordPress is vulnerable to Price Manipulation in all versions up to, and including, 2.8.1. This is d…

No fix yet
Fix from $1,600 2026-07-30
Data Master HIGH 8.1
CVE-2026-18188

A format string vulnerability was found in the Rsync Backup on the ADM. The vulnerability occurs because user-controlled rsync backup configuration o…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master HIGH 8.1
CVE-2026-18187

A format string vulnerability was found in the Internal Backup on the ADM. The vulnerability occurs because user-controlled task input may be include…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Data Master HIGH 8.1
CVE-2026-18186

A stored format string vulnerability was found in the FTP Backup on the ADM. The vulnerability occurs because user-controlled backup configuration da…

Fix: 5.1.4.rjv2+
Fix from $1,950 2026-07-30
Unclassified MEDIUM 6.5
CVE-2026-16092

The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field via 'Save and Duplicate' Action…

No fix yet
Fix from $1,600 2026-07-30
Unclassified HIGH 7.3
CVE-2026-16727

Concurrent Execution using Shared Resource with Improper Synchronization (“Race Condition”) in ASUS Armoury Crate allows a local user to execute arbi…

No fix yet
Fix from $1,950 2026-07-30
Unclassified HIGH 7.1
CVE-2026-15929

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in LG Electronics SmartShare allows SQL Injection.…

No fix yet
Fix from $1,950 2026-07-30
Chrome HIGH 8.8
CVE-2026-18017

Use after free in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTM…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-18015

Inappropriate implementation in Tint in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escape…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-18014

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restric…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Unclassified MEDIUM 6.9
CVE-2026-59952

Valibot helps validate data using a schema. Versions prior to 1.4.2 can throw a TypeError inside its flatten() helper when validation issues contain …

Patch available
Fix from $1,600 2026-07-30
Chrome HIGH 8.8
CVE-2026-18012

Use after free in PDFium in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted P…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-18005

Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-18002

Insufficient validation of untrusted input in Google Lens in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the r…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-18001

Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information f…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17999

Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain spoofing via a crafted HTML p…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome MEDIUM 6.2
CVE-2026-17996

Inappropriate implementation in Browser in Google Chrome on Mac prior to 151.0.7922.72 allowed a local attacker to bypass navigation restrictions via…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome HIGH 8.1
CVE-2026-17995

Out of bounds read in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform an out of bounds memory read via a crafted HT…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome HIGH 7.0
CVE-2026-17993

Race in Updater in Google Chrome on Windows prior to 151.0.7922.72 allowed a local attacker to perform privilege escalation via a malicious file. (Ch…

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30
Chrome MEDIUM 6.5
CVE-2026-17992

Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potentially sensitive information fr…

Fix: 151.0.7922.72+
Fix from $1,600 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17991

Insufficient validation of untrusted input in AI in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the renderer p…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome CRITICAL 9.6
CVE-2026-17990

Insufficient validation of untrusted input in WebAuthn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend…

Fix: 151.0.7922.72+
Fix from $2,300 2026-07-30
Chrome HIGH 8.8
CVE-2026-17989

Type Confusion in V8 in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML …

Fix: 151.0.7922.72+
Fix from $1,950 2026-07-30