Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-49080

Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-49079

Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-49076

Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-49075

Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-49058

Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-48875

Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-48797

Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI expo…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-48781

Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob int…

Patch available
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-48745

Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.1…

Patch available
Fix from $2,300 2026-06-17
Rocket.chat CRITICAL 9.3
CVE-2026-48616

Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file…

Fix: 7.10.13 / 7.13.9+
Fix from $2,300 2026-06-17
Unclassified CRITICAL 10.0
CVE-2026-48055

Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vul…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-42380

Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40783

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40749

Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40748

Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40747

Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-40746

Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-40725

Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-39596

Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-39589

Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-39529

Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.3
CVE-2026-39438

Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions.

Mitigation only
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.1
CVE-2026-32967

Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before…

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Dolphinscheduler CRITICAL 9.8
CVE-2026-32966

DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache …

Fix: 3.4.2+
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-27429

Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.8
CVE-2026-27395

Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-27041

Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 10.0
CVE-2026-25470

Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Cod…

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.9
CVE-2026-25446

Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions.

Mitigation only
Fix from $2,300 2026-06-17
Unclassified CRITICAL 9.1
CVE-2026-24611

Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions.

Mitigation only
Fix from $2,300 2026-06-17