Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-12877

The Project Management, Bug and Issue Tracking Plugin WordPress plugin before 5.1.0 does not sanitise and escape user supplied input before using it…

No fix yet
Fix from $2,300 2026-07-24
Unclassified MEDIUM 5.4
CVE-2026-12689

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its private-message thread actions,…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-12688

The ProfileGrid WordPress plugin before 5.9.9.7 does not verify PayPal IPN notifications before granting paid group membership, allowing unauthentic…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 7.5
CVE-2026-12497

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not …

No fix yet
Fix from $1,950 2026-07-24
Unclassified HIGH 8.8
CVE-2026-16870

Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltrati…

No fix yet
Fix from $1,950 2026-07-24
Exim HIGH 7.8
CVE-2026-66141

Exim before 4.99.5 allows .forward privilege escalation because force_command for a pipe transport is mishandled.

Fix: 4.99.5+
Fix from $1,950 2026-07-24
Exim HIGH 7.8
CVE-2026-66140

Exim before 4.99.5 allows directory traversal to access files outside of the spool area, and consequently gain privileges, because arguments related …

Fix: 4.99.5+
Fix from $1,950 2026-07-24
Unclassified HIGH 7.2
CVE-2026-66138

In OpenStack Ironic Python Agent through 11.6.0, a project-scoped user with the manager role can achieve arbitrary code execution on a running Ironic…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 5.5
CVE-2026-54422

In OpenStack Ironic Python Agent through 11.5.0, a malicious bootc container, when deployed using ironic-python-agent, may be able to extract the cre…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-6454

The Firelight Lightbox plugin for WordPress is vulnerable to Stored DOM Cross-Site Scripting in versions up to and including 2.3.20. This is due to i…

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2026-15100

The Post Grid Gutenberg Blocks – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'searchnoresult' Block Attribute in all …

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-13464

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Object Reference in all version…

No fix yet
Fix from $1,600 2026-07-24
Unclassified HIGH 8.0
CVE-2026-12736

The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::sa…

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.5
CVE-2026-11922

A vulnerability in zenml-io/zenml versions 0.57.0 through 0.94.2 allows an attacker to bypass rate-limiting on the `POST /api/v1/login` and self pass…

Patch available
Fix from $1,600 2026-07-24
Unclassified MEDIUM 5.3
CVE-2026-11354

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.7.8.3 via the …

No fix yet
Fix from $1,600 2026-07-24
Unclassified MEDIUM 6.4
CVE-2025-9205

The MapSVG plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 8.14.0. This is due to insufficien…

No fix yet
Fix from $1,600 2026-07-24
Azure Key Vault CRITICAL 9.8
CVE-2026-62825

Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Dns CRITICAL 9.8
CVE-2026-58275

Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Exchange Online CRITICAL 10.0
CVE-2026-56191

Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tampering over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Ai Search HIGH 8.8
CVE-2026-56167

Server-side request forgery (ssrf) in Azure AI Search allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $1,950 2026-07-24
Account CRITICAL 9.8
CVE-2026-56165

Heap-based buffer overflow in Microsoft Account allows an unauthorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
Azure Red Hat Openshift CRITICAL 9.9
CVE-2026-56160

Improper authorization in Azure Red Hat OpenShift (ARO) allows an authorized attacker to elevate privileges over a network.

No fix yet
Fix from $2,300 2026-07-24
Surface Management Services HIGH 8.8
CVE-2026-54120

Improper input validation in Microsoft Surface allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
365 Copilot CRITICAL 9.9
CVE-2026-50517

Deserialization of untrusted data in M365 Copilot allows an authorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-07-24
Graph MEDIUM 6.5
CVE-2026-49159

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

No fix yet
Fix from $1,600 2026-07-24
Azure Api Management HIGH 7.2
CVE-2026-35425

Improper access control in Azure API Management (APIM) allows an authorized attacker to execute code over a network.

No fix yet
Fix from $1,950 2026-07-24
Unclassified MEDIUM 6.8
CVE-2026-50044

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an inadequate encryption strength vulnerability which could allow an attacker to steal admin cred…

No fix yet
Fix from $1,600 2026-07-23
Unclassified MEDIUM 5.3
CVE-2026-44955

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized control sphere vulnerability which…

No fix yet
Fix from $1,600 2026-07-23
Unclassified CRITICAL 10.0
CVE-2026-42933

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerability which could allow an attacker to use an active …

Mitigation only
Fix from $2,300 2026-07-23
Unclassified HIGH 7.5
CVE-2026-40430

Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext storage of a password vulnerability that could expose cleartext credentials through t…

No fix yet
Fix from $1,950 2026-07-23