Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-49080 Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-49079 Unauthenticated SQL Injection in JetSearch <= 3.5.17 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-49076 Unauthenticated SQL Injection in JetEngine <= 3.8.9.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-49075 Contributor PHP Object Injection in JetEngine <= 3.8.9.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-49058 Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-48875 Unauthenticated SQL Injection in JetSmartFilters <= 3.8.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-48797 Backpropagate is a Python library for fine-tuning large language models on a single GPU. In versions 1.1.0 and 1.1.1, the optional Reflex web UI expo… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-48781 Postiz is an AI social media scheduling tool. In versions prior to 2.21.8, the Skool integration callback signed an attacker-controlled JSON blob int… Patch available Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-48745 Traccar Client is a GPS tracking mobile app for sending location updates to private servers using the open-source Traccar platform. In versions 9.7.1… Patch available Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-48616 Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file… Rocket.chat 7.10.13 / 7.13.9+ Fix from $2,3002026-06-17 CRITICAL 10.0 CVE-2026-48055 Streambert is a cross-platform Electron Desktop App to stream and download any video media. In versions 2.4.0 and prior, a high-severity Zip Slip vul… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-42380 Unauthenticated PHP Object Injection in AI Lab < 5.4.2 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40783 Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40749 Subscriber Arbitrary File Upload in Charity Zone <= 1.1.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40748 Subscriber Arbitrary File Upload in Kids Gift Shop <= 0.5.4 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40747 Subscriber Arbitrary File Upload in Ecommerce Zone <= 0.9.7 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-40746 Subscriber Arbitrary File Upload in Restaurant Zone <= 0.7.8 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-40725 Unauthenticated PHP Object Injection in WooCommerce Product Filters < 2.0.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-39596 Unauthenticated SQL Injection in Blocksy Companion Pro < 2.1.29 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-39589 Subscriber Arbitrary File Upload in Webenvo <= 0.0.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-39529 Unauthenticated PHP Object Injection in Elementra <= 1.0.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.3 CVE-2026-39438 Unauthenticated SQL Injection in ListingPro <= 2.9.10 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-32967 Incorrect Authorization vulnerability of `/v2` experimental interface in Apache DolphinScheduler. This issue affects Apache DolphinScheduler: before… Dolphinscheduler 3.4.2+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-32966 DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure in Apache DolphinScheduler. This issue affects Apache … Dolphinscheduler 3.4.2+ Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-27429 Unauthenticated PHP Object Injection in Nifty <= 1.4.1 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.8 CVE-2026-27395 Unauthenticated Privilege Escalation in Support Board < 3.8.9 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-27041 Contributor Arbitrary File Upload in Unlimited Elements for Elementor (Premium) <= 2.0.6 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 10.0 CVE-2026-25470 Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Cod… Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.9 CVE-2026-25446 Subscriber Arbitrary File Upload in WishList Member X <= 3.29.0 versions. Mitigation only Fix from $2,3002026-06-17 CRITICAL 9.1 CVE-2026-24611 Unauthenticated Broken Access Control in MetForm Pro <= 3.9.1 versions. Mitigation only Fix from $2,3002026-06-17