Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-74886

openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules tha…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74880

openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract t…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74878

openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on …

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74876

openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74875

openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata …

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.8
CVE-2026-74872

openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob pat…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.0
CVE-2026-74800

SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-si…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.3
CVE-2026-74799

SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.4
CVE-2026-15623

A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Clou…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 10.0
CVE-2026-19977

A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Va…

No fix yet
Fix from $5,750 2026-08-17
Unclassified CRITICAL 9.9
CVE-2026-19961

A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a …

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.9
CVE-2026-19959

A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This man…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-74790

Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to e…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-73061

Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-73056

SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware.…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-72887

Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Pass…

Patch available
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19349

Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass vi…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.3
CVE-2026-74251

Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specificat…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2024-13784

The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-19725

The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before usin…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-19714

The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-18316

The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-18432

The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnera…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-16098

The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_han…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.1
CVE-2026-14524

The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 9.8
CVE-2026-19924

A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th…

No fix yet
Fix from $5,750 2026-08-16
Unclassified CRITICAL 10.0
CVE-2026-74764

Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor p…

Patch available
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73053

SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73052

SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the…

No fix yet
Fix from $5,750 2026-08-15
Unclassified CRITICAL 9.0
CVE-2026-73050

SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu…

No fix yet
Fix from $5,750 2026-08-15