Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-66691

Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-66478

Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-66472

Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-66465

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-66458

Unauthenticated SQL Injection in RealPress <= 1.1.2 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-66453

Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-66446

Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-66436

Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-66424

Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-61969

Unauthenticated SQL Injection in Listdom <= 5.6.0 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-61967

Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-61966

Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-61962

Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-28185

Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-28149

Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-28148

Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-28142

Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-28008

Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-28001

Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 10.0
CVE-2026-27544

Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions.

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.8
CVE-2026-49827

WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u…

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73602

Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code …

Patch available
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73601

Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73487

Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73486

Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.0
CVE-2026-73485

Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.4
CVE-2026-73483

Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a…

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-59507

CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.3
CVE-2026-59506

CWE-306: Missing Authentication for Critical Function

No fix yet
Fix from $2,300 2026-08-13
Unclassified CRITICAL 9.1
CVE-2026-59504

CWE-602: Client-Side Enforcement of Server-Side Security

No fix yet
Fix from $2,300 2026-08-13