Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-73339

Unauthenticated SQL Injection in Modern Events Calendar < 7.35.0 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.3
CVE-2026-73187

Unauthenticated SQL Injection in Sticky Chat Widget <= 1.4.2 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-66627

Contributor Arbitrary File Upload in GP Premium <= 2.5.5 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to 1.5.3, seroval.fromJSON() all…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32474

Contributor Arbitrary File Upload in Templatiq <= 0.2.5 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32463

Contributor Arbitrary File Upload in Sync Post With Other Site <= 1.9.3 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-32444

Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-28192

Unauthenticated Arbitrary File Upload in Piotnet Addons For Elementor Pro <= 7.1.67 versions.

No fix yet
Fix from $5,750 2026-08-18
Firefox CRITICAL 10.0
CVE-2026-75874

Sandbox escape in the Remote Settings Client component. This vulnerability was fixed in Firefox 154 and Thunderbird 154.

Fix: 154.0 / 154.0.0+
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-75783

A security vulnerability has been detected in TRENDnet TEW-WLC100P 12.07b01. Affected by this vulnerability is an unknown functionality of the file /…

No fix yet
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74989

Internally found bugs present in Thunderbird 153. Some of these bugs showed evidence of memory corruption or another security-relevant defect and we …

Fix: 154.0 / 154.0.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74988

Internally found bugs present in Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corruption or another securi…

Fix: 153.1.0+
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-74986

Site isolation issue in the CSS Parsing and Computation component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, a…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-74985

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thund…

No fix yet
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74987

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corr…

Fix: 140.14.0 / 153.1.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74990

Internally found bugs present in Thunderbird ESR 140.13, Thunderbird ESR 153.0 and Thunderbird 153. Some of these bugs showed evidence of memory corr…

Fix: 115.39.0 / 140.14.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird …

Fix: 153.1.0 / 154.0+
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.1
CVE-2026-74959

Mitigation bypass in the Storage: Cache API component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbir…

No fix yet
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.1
CVE-2026-74961

Side-channel in the Web Audio component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 153.1.

Fix: 153.1.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74964

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154, Thun…

Fix: 140.14.0 / 153.1.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.1
CVE-2026-74956

Same-origin policy bypass in the DOM: Service Workers component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and…

Fix: 153.1.0 / 154.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74944

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderbird 154…

Fix: 140.14.0 / 153.1.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74943

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR …

Fix: 115.39.0 / 140.14.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74940

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox ESR 140.14, Firefox ESR 153.…

Fix: 115.39.0 / 140.14.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.1
CVE-2026-74938

Mitigation bypass in the JavaScript: GC component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderbird 154, and Thunderbird 1…

Fix: 153.1.0 / 154.0+
Fix from $5,750 2026-08-18
Firefox CRITICAL 9.8
CVE-2026-74936

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR 153.1, Thunderb…

Fix: 140.14.0 / 153.1.0+
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-75854

ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that allows unauthenticated attacker…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.8
CVE-2026-75852

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin. Unauthenticated attackers c…

No fix yet
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.9
CVE-2026-75851

ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command …

No fix yet
Fix from $5,750 2026-08-18