Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 6.5
CVE-2026-16079

The Fullscreen Galleria plugin for WordPress is vulnerable to generic SQL Injection via 'href' Attribute in Post Content in all versions up to, and i…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-15963

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to generic SQL Injection via 'randon_category' Quiz …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15726

The Serious Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'theme' Shortcode Attribute in all versions up to, and inclu…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 5.3
CVE-2026-15441

The WC Product Table Lite plugin for WordPress is vulnerable to CSS Injection in versions up to, and including, 5.6.0 via the 'laptop_scroll_offset' …

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-15066

The Loco Translate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via PO File Extracted Comments in all versions up to, and includ…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.1
CVE-2026-15009

The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.2
CVE-2026-15002

The Platnosci Online Blue Media (Autopay) plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.0 v…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-14524

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe…

No fix yet
Fix from $5,750 2026-08-16
Unclassified HIGH 8.8
CVE-2026-14498

The Query Wrangler plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.5.57 via the 'options' paramet…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.5
CVE-2026-13358

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.4
CVE-2026-11780

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'question_tit…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19930

A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User …

Patch available
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19929

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/ware…

Patch available
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19928

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/R…

Patch available
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19927

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/…

Patch available
Fix from $4,000 2026-08-16
Unclassified HIGH 7.3
CVE-2026-19926

A vulnerability has been found in Evergreen up to 3.14.11/3.15.11/3.16.5/3.17-beta1. The affected element is an unknown function of the file /osrf-ga…

No fix yet
Fix from $4,900 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19924

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th…

No fix yet
Fix from $5,750 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19923

A weakness has been identified in code-projects Online Shopping System 1.0. This affects an unknown part of the file /checkout_process.php. Executing…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19921

A vulnerability was identified in code-projects Online Shopping System 1.0. Affected by this vulnerability is an unknown functionality of the file /h…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19920

A vulnerability was determined in code-projects Online Shopping System 1.0. Affected is an unknown function of the file /action.php. This manipulatio…

No fix yet
Fix from $4,000 2026-08-16
Unclassified HIGH 7.3
CVE-2026-19919

A vulnerability was found in code-projects Online Shopping System 1.0. This impacts an unknown function of the file /login.php of the component Login…

No fix yet
Fix from $4,900 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19918

A vulnerability has been found in SpaceX Starlink Router Gen 3 2025.11.14.mr64708.3. This affects the function get_status of the component gRPC Manag…

No fix yet
Fix from $4,000 2026-08-16
Unclassified MEDIUM 6.3
CVE-2026-19917

A flaw has been found in code-projects Online Food Order System 1.0. The impacted element is an unknown function of the file delete_food_items1.php. …

No fix yet
Fix from $4,000 2026-08-15
Unclassified HIGH 8.7
CVE-2026-74767

Pandora contains a denial-of-service vulnerability in its handling of DAA (Direct Access Archive) files. When extracting the internal ISO image from …

Patch available
Fix from $4,900 2026-08-15
Unclassified CRITICAL 10.0
CVE-2026-74764

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor p…

Patch available
Fix from $5,750 2026-08-15
Unclassified HIGH 7.5
CVE-2026-73054

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the WebSocket endpoint caused by differential parsing of query parame…

No fix yet
Fix from $4,900 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73053

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73052

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73050

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu…

No fix yet
Fix from $5,750 2026-08-15
Unclassified MEDIUM 6.2
CVE-2026-73047

siyuan versions <= 3.7.3 (fixed in v3.7.4) contain a server-side template injection vulnerability in the attribute-view Template calculation feature …

No fix yet
Fix from $4,000 2026-08-15