Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-18615

A vulnerability was determined in GL-iNet GL-MT3000 up to 4.4.5. The affected element is the function wg-server.generate_publickey of the file /cgi-b…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18614

A vulnerability was found in GL-iNet GL-MT3000 up to 4.4.5. Impacted is the function s2s.enable_echo_server of the file /cgi-bin/glc of the component…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18613

A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the c…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18612

A flaw has been found in GL-iNet GL-MT3000 up to 4.4.5. This vulnerability affects the function plugins.remove_package/plugins.install_package of the…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-41452

Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrit…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-39932

OpenEMR through 8.2.0 contains a remote code execution vulnerability in the document category tree component (library/classes/Tree.class.php) that al…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18602

A vulnerability was determined in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function ovpn-client.get_recommend_config of the file /cgi-bin/glc o…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-18248

@fastify/aws-lambda version 6.4.0 decorates each Fastify request with request.awsLambda.event and request.awsLambda.context, values that applications…

No fix yet
Fix from $2,300 2026-08-03
\ CRITICAL 9.1
CVE-2026-9487

XML::Sig versions before 0.71 for Perl allow signature wrapping via duplicate ID. _get_signed_xml() in lib/XML/Sig.pm, called from verify(), resolve…

Fix: 0.71+
Fix from $2,300 2026-08-03
\ CRITICAL 9.1
CVE-2026-9390

XML::Sig versions before 0.71 for Perl allow XPath injection in ID lookup. verify() and _get_signed_xml() in lib/XML/Sig.pm build XPath expressions …

Fix: 0.71+
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69085

SiYuan before v3.7.3 contains a SQL injection vulnerability in the /api/filetree/searchDocs endpoint, where the caller-supplied keyword parameter is …

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69084

SiYuan versions <= v3.7.2 expose the /api/search/searchEmbedBlock endpoint, which passes a client-supplied SQL statement verbatim to the main read-wr…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-69083

SiYuan versions before v3.7.3 contain SQL injection vulnerabilities in the fullTextSearchAssetContent endpoint reachable by unauthenticated users and…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-64827

Telenia Software TVox 26.5.3 and prior 26.x versions, and 24.9.21 and prior 24.x versions, contain an authentication bypass vulnerability in set_env.…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18601

A vulnerability was found in GL.iNet GL-MT3000 up to 4.4.5. This impacts the function ovpn-client.check_config of the file /cgi-bin/glc of the compon…

No fix yet
Fix from $2,300 2026-08-03
Net\ CRITICAL 9.8
CVE-2026-18108

Net::SAML2 versions before 0.86 for Perl allow authentication bypass because _verify_encrypted_assertion accepts an EncryptedAssertion whose decrypte…

Fix: 0.86+
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-2346

Authorization bypass through User-Controlled key vulnerability in Menulux Software Inc. Mobile App allows Software Integrity Attack. This issue affe…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.3
CVE-2026-18574

An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an una…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 10.0
CVE-2026-33591

A vulnerability in Wapt Server before version 2.6.1.17813 allows a  remote unauthenticated attacker to bypass security restriction using a specially …

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18589

A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of th…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-18588

A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the arg…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-16534

The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-16532

The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16300

The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16250

The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-16060

The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.4
CVE-2026-15930

The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value …

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.8
CVE-2026-12872

The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio…

No fix yet
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-14557

The SoftMarket — Digital Marketplace WordPress plugin through 1.0.0 does not properly validate an authentication token in one branch of its email-ver…

Mitigation only
Fix from $2,300 2026-08-03
Unclassified CRITICAL 9.1
CVE-2026-12965

The Super Store Finder WordPress plugin through 7.8 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, a…

No fix yet
Fix from $2,300 2026-08-03