Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.9
CVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.5
CVE-2026-66622

Unauthenticated SQL Injection in Depicter Slider <= 4.8.0 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-66621

Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard <= 3.11.2 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-66620

Editor PHP Object Injection in OptionTree <= 2.7.3 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-66046

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.c, …

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-63639

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's RESTORE command accepts a malformed RDB stream…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-61407

Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an Exposed IOCTL with Insufficient Access Control vulnerability. A low privileged attack…

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.5
CVE-2026-59949

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the …

Patch available
Fix from $4,000 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all…

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.4
CVE-2026-59825

Mastodon is a free, open-source social network server based on ActivityPub. Prior to 4.4.19 and from 4.5.0 until 4.5.12, Mastodon's app/models/concer…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-56684

Valkey is a distributed key-value database. Prior to 7.2.14, 8.0.10, 8.1.9, 9.0.5, and 9.1.1, Valkey's tlsProcessPendingData function iterates pendin…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-50187

Oh My Zsh is a community-driven framework for managing Zsh configuration. Prior to 2026-05-28, the dotenv plugin in plugins/dotenv/dotenv.plugin.zsh …

Patch available
Fix from $4,900 2026-08-18
Unclassified MEDIUM 5.9
CVE-2026-50139

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, `ShareHandler` reads the share token's `DownloadLimit` under `RLock`, releases the…

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.1
CVE-2026-50138

goshs is a SimpleHTTPServer written in Go. Prior to version 2.1.0, when `goshs` is launched with WebDAV enabled (`-w`), the mode-restriction flags `-…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-48798

SSH.NET is a Secure Shell (SSH) library for .NET. In 2025.1.0 and earlier, ScpClient.Download(string directoryName, DirectoryInfo directoryInfo) trus…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 8.3
CVE-2026-45733

Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #ic…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.2
CVE-2026-32553

Unauthenticated Server Side Request Forgery (SSRF) in OttoKit <= 1.1.35 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-32549

Unauthenticated Broken Access Control in ThumbPress < 6.5 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.1
CVE-2026-32547

Unauthenticated Cross Site Scripting (XSS) in BP Better Messages <= 2.15.22 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-32481

Unauthenticated Broken Authentication in Ezoic <= 2.22.11 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.2
CVE-2026-32473

Unauthenticated Server Side Request Forgery (SSRF) in PDF Smart Viewer for Elementor <= 1.0.4 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-32472

Unauthenticated Broken Access Control in Online Contact Widget <= 1.3.0 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified HIGH 7.4
CVE-2026-18534

ArcSearch for iOS versions prior to 1.48.0 could keep the address bar hidden after a page-initiated scroll, allowing attacker-controlled content to i…

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 7.7
CVE-2026-50575

BetterDesk is a remote desktop management solution. BetterDesk versions through 2.3.0 improperly invalidate deleted device identities, allowing an un…

Patch available
Fix from $4,900 2026-08-18
Unclassified HIGH 7.5
CVE-2026-32468

Unauthenticated Sensitive Data Exposure in Duitku Payment Gateway <= 2.11.14 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified MEDIUM 6.0
CVE-2026-32467

Subscriber Server Side Request Forgery (SSRF) in [Aotuman] Grab WeChat Articles <= 2.0.1 versions.

No fix yet
Fix from $4,000 2026-08-18
Unclassified HIGH 8.5
CVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

No fix yet
Fix from $4,900 2026-08-18
Unclassified HIGH 8.8
CVE-2026-32465

Customer PHP Object Injection in Essential Real Estate <= 5.3.3 versions.

No fix yet
Fix from $4,900 2026-08-18