Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.1
CVE-2026-73073

Vim is an open source, command line text editor. Prior to 9.2.0845, StructMembers() in runtime/autoload/ccomplete.vim constructs and executes a vimgr…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.1
CVE-2026-72532

Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allow…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.5
CVE-2026-71574

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check a…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.7
CVE-2026-71477

mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.7.1, release tar archives record mise/bin/mise with user and group ID 1…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 7.7
CVE-2026-71365

A server-side request forgery (SSRF) vulnerability was found in AWX's webhook status callback mechanism. When processing GitHub pull request webhooks…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.8
CVE-2026-63328

Trivy is a security scanner. Prior to 0.72.0, plugin manifest metadata is used by pkg/plugin/manager.go to construct paths under ~/.trivy/plugins wit…

Patch available
Fix from $4,000 2026-08-18
Unclassified HIGH 8.8
CVE-2026-62357

Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.40.0, CMS.INITBYDIM and CMS.INITBYPROB accept dimensions whos…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-55839

Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, Kestra's custom Markdown parser in ui/src/utils/markdown_plugins/link…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.6
CVE-2026-49227

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend comment opera…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-49226

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend post operatio…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-49221

Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset…

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-46482

### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challe…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-45734

MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remot…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-45125

MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail h…

Patch available
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.4
CVE-2026-45120

MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-45118

MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-45117

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura…

Patch available
Fix from $5,750 2026-08-18
Unclassified HIGH 8.7
CVE-2026-45116

MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field …

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.7
CVE-2026-45115

MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-19500

The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or sub…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.0
CVE-2026-15806

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d…

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-12564

A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.5
CVE-2026-75898

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The …

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.9
CVE-2026-75872

HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send …

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 10.0
CVE-2026-75784

A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx …

No fix yet
Fix from $5,750 2026-08-18
Unclassified MEDIUM 6.3
CVE-2026-75032

A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile …

No fix yet
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-74015

Unauthenticated SQL Injection in Readabler < 2.0.18 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 8.8
CVE-2026-74012

Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0.

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-74009

Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions.

No fix yet
Fix from $4,000 2026-08-18
Unclassified MEDIUM 5.3
CVE-2026-74008

Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions.

No fix yet
Fix from $4,000 2026-08-18