Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.3
CVE-2026-66649

Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-66609

Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-66600

Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-66593

Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2026-66592

Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-66583

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2025-15689

Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.3
CVE-2025-15688

Unauthenticated SQL Injection in Capella <= 2.5.5 versions.

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.1
CVE-2026-13097

A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.6
CVE-2026-11861

A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-14950

An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-75860

The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r…

No fix yet
Fix from $5,750 2026-08-20
Unclassified CRITICAL 9.8
CVE-2026-76850

LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py r…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76590

A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cg…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76589

A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the …

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.1
CVE-2026-76404

In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating …

No fix yet
Fix from $5,750 2026-08-19
Splunk CRITICAL 9.4
CVE-2026-76312

In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) sou…

Fix: 9.4.14 / 10.0.9+
Fix from $5,750 2026-08-19
Splunk CRITICAL 9.4
CVE-2026-76311

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d…

Fix: 9.4.14 / 10.0.9+
Fix from $5,750 2026-08-19
Splunk CRITICAL 9.4
CVE-2026-76310

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a…

Fix: 9.4.14 / 10.0.9+
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76584

A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.1
CVE-2026-75595

Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHand…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.6
CVE-2026-53548

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.6
CVE-2026-53546

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket …

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-53545

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-63722

ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands b…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-55089

Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in th…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.6
CVE-2026-55085

Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a num…

Patch available
Fix from $5,750 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-22306

Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive informat…

No fix yet
Fix from $5,750 2026-08-19
Aix CRITICAL 9.8
CVE-2026-16919

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied …

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19
Vios CRITICAL 9.8
CVE-2026-16917

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow.

Fix: 4.1.0.50 / 4.1.1.30+
Fix from $5,750 2026-08-19