Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.1
CVE-2026-76242

stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-band fingerprint approval …

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-74804

Joomla Extension - yootheme.com - Unauthenticated SQL injection in ItemController::element() in Zoo < 4.1.64 - The filter_type request value is inter…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-74803

Joomla Extension - yootheme.com - Unauthenticated arbitrary file upload in Zoo < 4.1.64 - The image element accepts arbitrary files when the client-s…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-16019

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Faydam Innovation Inc. FAYDAM Datalogger allows…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73391

Unauthenticated SQL Injection in Total Donations <= 2.0.5 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73390

Unauthenticated Privilege Escalation in Total Donations <= 2.0.5 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73389

Unauthenticated PHP Object Injection in Kalles Addons <= 1.0.6 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73388

Unauthenticated SQL Injection in Nikstore Core <= 1.5 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73364

Customer PHP Object Injection in Flexible Subscriptions <= 1.8.1 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-73347

Unauthenticated Privilege Escalation in TrueBooker <= 1.2.6 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73185

Unauthenticated SQL Injection in NGG Smart Image Search < 4.0.0 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-73183

Unauthenticated SQL Injection in Maps Marker Pro <= 4.32 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-67364

Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - CWE-94 / CWE-95 | CVSS 3.1: 9.8 Critical (AV:N/AC:L/PR:N/UI…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-66613

Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.14 versions.

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-19490

Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.0
CVE-2026-18937

The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalink…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-18776

The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-18051

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthentic…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.8
CVE-2026-18031

The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated wi…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 10.0
CVE-2026-76008

A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the function get_para_from_uri of the file /cgi-bin/mbox-config of the component URI P…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76004

A security vulnerability has been detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of th…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-76003

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is the function strcpy of the file /goform/formGroupConfig. Executing…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.1
CVE-2026-11751

A vulnerability has been identified in armeria-xds versions prior to 1.41.0, where xDS upstream TLS peer verification may be silently disabled, allow…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.9
CVE-2026-75976

A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file /cgi-bin/wan.cgi of the component NVRAM.…

No fix yet
Fix from $5,750 2026-08-19
Unclassified CRITICAL 9.3
CVE-2026-21580

This Critical severity Stored XSS, PrivEsc (Privilege Escalation), and Security Misconfiguration vulnerability was introduced in versions 7.1.1, 7.4.…

No fix yet
Fix from $5,750 2026-08-18
Chrome CRITICAL 9.6
CVE-2026-76036

Buffer overflow in Dawn in Google Chrome on on Android prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside the sandbo…

Fix: 151.0.7922.169+
Fix from $5,750 2026-08-18
Unclassified CRITICAL 9.6
CVE-2026-76035

Inappropriate implementation in Media in Google Chrome on on Mac prior to 151.0.7922.169 allowed a remote attacker to execute arbitrary code outside …

No fix yet
Fix from $5,750 2026-08-18
Helidon CRITICAL 9.9
CVE-2026-73930

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 4.5.…

No fix yet
Fix from $5,750 2026-08-18
Helidon CRITICAL 9.1
CVE-2026-73924

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.…

No fix yet
Fix from $5,750 2026-08-18
Helidon CRITICAL 9.1
CVE-2026-73922

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). The supported version that is affected is 1.4.…

No fix yet
Fix from $5,750 2026-08-18