Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-71945

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-71944

D-Link DWR-M961 devices with hardware version C1 and firmware version before 1.1.5_C1_202607071108 contain a command injection vulnerability in the /…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-68082

In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cl…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.8
CVE-2026-14526

The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du…

No fix yet
Fix from $2,300 2026-08-08
Unclassified CRITICAL 9.6
CVE-2026-46409

OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.1
CVE-2026-48170

`scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value`…

Patch available
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-47243

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.6
CVE-2026-50540

Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P…

Patch available
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-61808

LightRAG provides simple and fast retrieval-augmented generation. Through version 1.5.4, the LightRAG API server binds to all network interfaces with…

Patch available
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.1
CVE-2026-48039

Meta Ads MCP is a Model Context Protocol (MCP) server that lets AI assistants run Meta Ads. Prior to version 1.0.109, `AuthInjectionMiddleware.dispat…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.0
CVE-2026-71851

crypto-js is a JavaScript library of crypto standards. Versions of crypto-js prior to 4.0.0 generate randomness in CryptoJS.lib.WordArray.random() us…

Patch available
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.9
CVE-2026-64637

Improper privilege management in the XML-RPC API of Plesk before 18.0.80, allows an authenticated reseller to obtain an administrative session for th…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-19264

Postiz is an open-source social media scheduling tool. The route that serves locally stored media joins URL-supplied path segments onto the upload di…

Patch available
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2022-4995

Weaver (Fanwei) E-cology 9.0 versions prior to 10.52 contain a file upload vulnerability that allows a remote, unauthenticated attacker to upload arb…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-66914

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download file…

No fix yet
Fix from $2,300 2026-08-07
Openmanage Server Administrator CRITICAL 9.8
CVE-2026-56793

Dell OpenManage Server Administrator, versions prior to 11.1.0.2, contains an Improper Authentication vulnerability. An unauthenticated attacker with…

Fix: 11.1.0.2+
Fix from $2,300 2026-08-07
Fory CRITICAL 9.1
CVE-2026-71560

Out-of-bounds Read vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0 when deser…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Fory CRITICAL 9.8
CVE-2026-71558

Heap type confusion vulnerability in Apache Fory C++ deserialization. This issue affects Apache Fory C++ versions from 0.14.0 before 1.5.0. A crafte…

Fix: 1.5.0+
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-54213

Tobit Laboratories AG TeamDavid's Webbox application exposes a functionality that allows the server to be shut down when a specific endpoint (/inter…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.5
CVE-2026-54212

Tobit Laboratories AG TeamDavid's Webbox application implements an API endpoint that is vulnerable to a buffer overflow condition. By submitting a s…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.5
CVE-2026-54211

Tobit Laboratories AG TeamDavid's Webbox application’s endpoint “//serverClient_close.html” is vulnerable to a buffer overflow vulnerability in mult…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.5
CVE-2026-54210

Tobit Laboratories AG TeamDavid's Webbox application implements various file upload functionalities that are vulnerable to a buffer overflow conditi…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.2
CVE-2026-54203

Memory Leak to an Unauthorized Actor vulnerability in Tobit Laboratories AG TeamDavid's Webbox allows reading of sensitive information. When accessin…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-16258

The Ajax Search Lite WordPress plugin before 4.14.5 does not prevent the deserialization of untrusted input, allowing unauthenticated attackers to p…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.1
CVE-2026-16038

The MStore API WordPress plugin before 4.21.0 does not verify the payment with the payment gateway before marking an order as paid on several of its…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-14205

The WP Events Manager WordPress plugin before 2.2.5 does not validate the requested quantity when registering for a paid event and computes the price…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-14365

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inclu…

No fix yet
Fix from $2,300 2026-08-07
Unclassified CRITICAL 9.8
CVE-2026-14364

The TrueBooker – Appointment Booking and Scheduler System plugin for WordPress is vulnerable to account takeover via improper password reset validati…

No fix yet
Fix from $2,300 2026-08-07
Sharepoint Online CRITICAL 9.6
CVE-2026-70332

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an unauthorized attacker t…

No fix yet
Fix from $2,300 2026-08-07
Azure Confidential Ledger CRITICAL 9.1
CVE-2026-68823

Exposed dangerous method or function in Azure Confidential Ledger allows an authorized attacker to execute code over a network.

No fix yet
Fix from $2,300 2026-08-07