Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-71256

nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71254

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in …

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71248

Inventory-Management-System-PHP's login.php constructs its authentication query via direct string concatenation of raw POST parameters: = "select * f…

Patch available
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71238

DjangoCRM ships with its Django SECRET_KEY hardcoded directly in the committed webcrm/settings.py rather than read from an environment variable. Sinc…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71237

Miantang/IoT-PHP's index.php implements a POST /userlogin route that reads the password directly from ['pwd'] with no sanitization and concatenates i…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71231

IOTSmartHome's gui/login.php checkCookie function builds an authentication query as SELECT * FROM users WHERE ID='<decoded lastLogin cookie>' after b…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-66747

Zbtlink router firmware ships an embedded remote-control implant, ENDLESSDOORS, present in every published build across the product line. It is the o…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-44945

A privilege escalation vulnerability exists in Rancher's impersonation middleware (pkg/auth/requests/impersonate.go). An authenticated Rancher user w…

Patch available
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.0
CVE-2026-10090

A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernet…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-10059

A flaw was found in the Multicluster Engine for Kubernetes ClusterCurator controller. A tenant administrator with namespace-scoped privileges can exp…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71214

The Aerie/PlanDev sequencing-server's authorization middleware (sequencing-server/src/app.ts) derives the caller's Hasura session role via getHasuraS…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-71213

Typemill's login endpoint (POST /tm/login, ControllerWebAuth::login) performs no rate-limiting, failed-attempt counting, or account lockout when capt…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-71207

The Stock-Inventory-Management-System application's login.php assigns raw username/password values to and builds its authentication query by directly…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.6
CVE-2026-70376

Pluck CMS's admin panel relies solely on a Referer-header comparison (requestedByTheSameDomain in data/inc/functions.admin.php, gating every admin.ph…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.8
CVE-2026-64566

In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags() When iptfs_sk…

No fix yet
Fix from $2,300 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61486

** UNSUPPORTED WHEN ASSIGNED ** Stack-based Buffer Overflow vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As this pro…

No fix yet
Fix from $2,300 2026-08-05
Lucy CRITICAL 9.8
CVE-2026-61484

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Lucy. This issue affects Apache Lucy: all versions. As th…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-5581

The Multi Uploader for Gravity Forms plugin for WordPress is vulnerable to unauthorized arbitrary media deletion in all versions up to, and including…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-4431

The Easy Post Submission plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `create_pos…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 10.0
CVE-2026-16940

The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-15360

The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthen…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-15210

The OTP Login With Phone Number, OTP Verification WordPress plugin before 1.8.71 does not limit the number of OTP verification attempts or invalidate…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.3
CVE-2026-9273

The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading t…

Mitigation only
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-45537

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the construct_uri() function concate…

Patch available
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-45100

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in …

Patch available
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-70554

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-control…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.1
CVE-2026-67979

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary …

Mitigation only
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-66902

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable sub…

Patch available
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-45538

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longe…

No fix yet
Fix from $2,300 2026-08-04
Unclassified CRITICAL 9.8
CVE-2026-70553

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application co…

No fix yet
Fix from $2,300 2026-08-04