Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-18367

A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 a…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-17032

Multiple Supsystic Pro plugins were distributed with malicious code through the vendor's compromised update server, allowing unauthenticated attacker…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-15734

A Server-Side Template Injection (SSTI) vulnerability in WGDashboard version 4.3.2 and earlier, allows authenticated attackers to execute arbitrary c…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-15733EPSS 14%

A Remote Code Execution (RCE) vulnerability exist in WGDashboard version 4.2.3 and earlier. Multiple OS command injection allows authenticated attack…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-15732

A Server-Side Request Forgery (SSFR) vulnerability exist in WGDashboard version 4.2.3 and earlier. The webhook functionality allows authenticated att…

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 10.0
CVE-2026-14812

The Premium SEO WordPress plugin is malicious: it ships an unauthenticated backdoor that creates a hidden administrator account and, in some builds, …

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 10.0
CVE-2026-11976

The official MonsterInsights Pro update distribution bucket (`monster-insights.s3.amazonaws.com`) was compromised. Both the current release (10.2.2) …

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.0
CVE-2025-14561

In multi-tenant deployments, the Publisher REST APIs fail to enforce tenant isolation correctly. This allows a user in one tenant, possessing suffici…

No fix yet
Fix from $2,300 2026-08-06
Virtual Storage Integrator CRITICAL 9.8
CVE-2026-67261

Dell Virtual Storage Integrator for VMware vSphere Client, versions prior to 10.11.1.0, contain(s) an OS Command Injection vulnerability in the IAPI …

Fix: 10.11.1.0+
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.1
CVE-2026-66709

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 10.0
CVE-2026-66665

Unauthenticated Arbitrary File Upload in Type Hub <= 2.0.6 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-66662

Unauthenticated Privilege Escalation in Frontend Admin by DynamiApps <= 3.29.10 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-66447

Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65581

Unauthenticated PHP Object Injection in AI ANN <= 1.29.0 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65579

Unauthenticated PHP Object Injection in Agricola <= 1.21.0 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65578

Unauthenticated PHP Object Injection in Agora <= 1.9 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65577

Unauthenticated PHP Object Injection in Advice <= 1.18.0 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65576

Unauthenticated PHP Object Injection in Adrena <= 1.2.14 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65575

Unauthenticated PHP Object Injection in Accalia <= 1.5.3 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65574

Unauthenticated PHP Object Injection in Abogado <= 1.18 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65573

Unauthenticated PHP Object Injection in Abelle <= 1.22 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65572

Unauthenticated PHP Object Injection in A.Williams <= 1.3.1 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65571

Unauthenticated PHP Object Injection in 69 Clothing <= 1.2.11.1 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65556

Unauthenticated PHP Object Injection in WPBruiser {no- Captcha anti-Spam} <= 3.1.43 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 10.0
CVE-2026-65553

Unauthenticated Remote Code Execution (RCE) in Spider Analyser &#8211; WordPress搜索引擎蜘蛛分析插件 <= 2.1.3 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.8
CVE-2026-65552

Subscriber PHP Object Injection in Export User Data <= 2.2.6 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.9
CVE-2026-65548

Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-65546

Unauthenticated SQL Injection in Qode Tours <= 3.1.3.1 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-65520

Unauthenticated SQL Injection in WP OAuth Server <= 6.2.0 versions.

No fix yet
Fix from $2,300 2026-08-06
Unclassified CRITICAL 9.3
CVE-2026-65508

Unauthenticated SQL Injection in Simply Schedule Appointments <= 1.6.12.10 versions.

No fix yet
Fix from $2,300 2026-08-06