Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-16051

The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, no…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-15039

The giftware WordPress plugin before 4.2.10 does not validate the type of uploaded files in one of its upload paths, allowing unauthenticated users t…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.9
CVE-2026-72526

A flaw was found in the multicloud-integrations component. The Application propagation controller processes the `ocm-managed-cluster` annotation from…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.6
CVE-2026-70398

A flaw was found in multicloud-integrations, a component of Red Hat Advanced Cluster Management (RHACM). This vulnerability allows an authenticated u…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.1
CVE-2026-68431

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate minimum PDU size for transform requests The receive path applie…

No fix yet
Fix from $2,300 2026-08-12
Unclassified CRITICAL 9.8
CVE-2026-68067

The login endpoint on the Mira cloud API accepts any format-valid string in the password field and returns a live active session token for the accoun…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-67568

The distributed Mira Android APK v4.5.15.4 allows an attacker read/write access to reproductive health profiles from internet connected hosts, which …

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-5917

libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH backend (USE_SSH=libssh2) contain a shell command injection vulnerability that all…

No fix yet
Fix from $2,300 2026-08-11
Httpclient CRITICAL 9.1
CVE-2026-71290

Improper TLS hostname verification vulnerability in Apache HttpComponents Client 5.4 or newer. HostnameVerificationPolicy#BUILTIN setting has no effe…

Fix: 5.6.4+
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.4
CVE-2026-66147

An unauthenticated command injection vulnerability was identified in the GMS Dispatcher Service in GMS 9.5.1 and earlier versions which allows remote…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.9
CVE-2026-48765

TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a low-privilege read collaborator to extract a workspace OAuth `credentialsId` from…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-73034

DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files to any location on the s…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-73032

PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerability that allows attackers to execute arbitrary JavaScript by returning maliciou…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-66145

An unauthenticated remote code execution vulnerability was identified in GMS 9.5.1 (Build 9510.1044) and earlier versions which allows remote attacke…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-45618

LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with crafted templa…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-16230

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file fun…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-73211

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.1.6, ActorFollowModel.updateScore() interpolates the attacker-controlled Ac…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.3
CVE-2026-73090

PeerTube is an ActivityPub-federated video streaming platform. Prior to 8.2.2, processUpdateActivity and processUpdateVideo accept an ActivityPub Upd…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-71398

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-71362

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vul…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.8
CVE-2026-69102

MaxKey contains an unauthorized access vulnerability due to a hard-coded JWT signing secret in application-maxkey.properties that allows unauthentica…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.0
CVE-2026-48381

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability tha…

No fix yet
Fix from $2,300 2026-08-11
Unclassified CRITICAL 9.6
CVE-2026-47705

TypeBot is a chatbot builder tool. Version 3.16.1 has a CSV injection vulnerability in the result export functionality. The application does not sani…

Patch available
Fix from $2,300 2026-08-11
Unclassified CRITICAL 10.0
CVE-2026-27302

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of …

No fix yet
Fix from $2,300 2026-08-11
Coldfusion CRITICAL 9.6
CVE-2026-71384

is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability…

No fix yet
Fix from $2,300 2026-08-11
Sharepoint Server CRITICAL 9.3
CVE-2026-70306

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

Fix: 16.0.19725.20434+
Fix from $2,300 2026-08-11
Allura CRITICAL 9.1
CVE-2026-69223

Apache Allura's webhooks are vulnerable to Server-Side Request Forgery (SSRF). This issue affects Apache Allura: before 1.19.1. Users are recommend…

Fix: 1.19.1+
Fix from $2,300 2026-08-11
Windows 10 1607 CRITICAL 9.8
CVE-2026-65791

Heap-based buffer overflow in Windows iSCSI Target Service allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $2,300 2026-08-11
Teams CRITICAL 9.8
CVE-2026-65768

Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Teams for Android allows an unauthorized attacker to exec…

Fix: 1.0.0.2026133602+
Fix from $2,300 2026-08-11
Windows 10 1607 CRITICAL 9.8
CVE-2026-62893

Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.

Fix: 10.0.14393.9418 / 10.0.17763.9115+
Fix from $2,300 2026-08-11