Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.6 CVE-2026-12294 Sandbox escape in the DOM: Workers component. This vulnerability was fixed in Firefox 152, Firefox ESR 140.12, Firefox ESR 115.37, Thunderbird 152, a… Firefox 115.37.0 / 140.12.0+ Fix from $2,3002026-06-16 CRITICAL 9.9 CVE-2026-40750 Unrestricted Upload of File with Dangerous Type vulnerability in themagnifico52 Kids Online Store allows Upload a Web Shell to a Web Server. This is… Mitigation only Fix from $2,3002026-06-16 CRITICAL 9.3 CVE-2026-52715 Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions. Mitigation only Fix from $2,3002026-06-16 CRITICAL 9.9 CVE-2026-49774 Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects R… Mitigation only Fix from $2,3002026-06-16 CRITICAL 9.3 CVE-2026-49772 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events Calendar allo… Mitigation only Fix from $2,3002026-06-16 CRITICAL 9.3 CVE-2026-39574 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions. Mitigation only Fix from $2,3002026-06-16 CRITICAL 9.8 CVE-2026-9261 Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 CRITICAL 9.8 CVE-2026-9260 Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 CRITICAL 9.8 CVE-2026-9259 Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 CRITICAL 9.8 CVE-2026-9258 Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Eos Network Setting Tool 1.5.1+ Fix from $2,3002026-06-16 CRITICAL 9.2 CVE-2026-48853 Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated … Patch available Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-12205 Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signat… Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-48714 i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7,… I18next Http Middleware 3.9.7+ Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-48713 Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via… I18next Fs Backend 2.6.6+ Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-12087 Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument … Patch available Fix from $2,3002026-06-15 CRITICAL 9.1 CVE-2026-11832 Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the … Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-9691 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.6 CVE-2026-52703 Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.3 CVE-2026-52693 Unauthenticated SQL Injection in eCommerce Product Catalog <= 3.5.5 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49781 Unauthenticated PHP Object Injection in OttoKit <= 1.1.27 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.3 CVE-2026-49776 Unauthenticated SQL Injection in GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites <= 2.32.6 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49770 Unauthenticated PHP Object Injection in WP Travel Engine <= 6.7.12 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49769 Unauthenticated PHP Object Injection in wpForo Forum <= 3.1.0 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49768 Unauthenticated PHP Object Injection in Happyforms <= 1.26.13 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.9 CVE-2026-49766 Subscriber Arbitrary File Deletion in WP User Manager <= 2.9.16 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49765 Unauthenticated PHP Object Injection in Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.8 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49764 Unauthenticated Broken Authentication in RegistrationMagic <= 6.0.8.6 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49763 Unauthenticated PHP Object Injection in Integration for Contact Form 7 HubSpot <= 1.3.7 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49109 Unauthenticated PHP Object Injection in Integration for Salesforce and Contact Form 7, WPForms, Elementor, Formidable, Ninja Forms <= 1.4.3 versions. Mitigation only Fix from $2,3002026-06-15 CRITICAL 9.8 CVE-2026-49106 Unauthenticated PHP Object Injection in Integration for Contact Form 7 and Constant Contact <= 1.1.6 versions. Mitigation only Fix from $2,3002026-06-15