Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-74886 openssl_encrypt versions before 1.4.0 contain a plugin sandbox bypass vulnerability where the PluginImportGuard blocks a different set of modules tha… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74880 openssl_encrypt versions before 1.4.0 accept refresh tokens as URL query parameters in keyserver and telemetry server routes. Attackers can extract t… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74878 openssl_encrypt versions before 1.4.0 use an in-memory rate limiter for TOTP brute-force protection that is not shared across workers and is lost on … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74876 openssl_encrypt versions before 1.4.0 contain a vulnerability in PublicKeyBundle.from_dict() that creates key bundles from untrusted data without ver… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74875 openssl_encrypt versions before 1.4.0 silently skip JSON schema validation when the jsonschema library is not installed, allowing malformed metadata … No fix yet Fix from $5,7502026-08-17 CRITICAL 9.8 CVE-2026-74872 openssl_encrypt versions before 1.4.0 contain an arbitrary code execution vulnerability in the Whirlpool hash implementation that uses broad glob pat… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.0 CVE-2026-74800 SiYuan before v3.7.4 fails to set Content-Disposition and X-Content-Type-Options headers when serving arbitrary file assets, allowing stored cross-si… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.3 CVE-2026-74799 SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not set… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.4 CVE-2026-15623 A SQL Injection vulnerability in a legacy dashboard widget API in Google Cloud Google SecOps (Chronicle SOAR) versions prior to 6.3.85 on Google Clou… No fix yet Fix from $5,7502026-08-17 CRITICAL 10.0 CVE-2026-19977 A vulnerability was detected in EFM ipTIME A3004T 14.19.0. The affected element is the function httpcon_check_session_url of the component Session Va… No fix yet Fix from $5,7502026-08-17 CRITICAL 9.9 CVE-2026-19961 A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing a … No fix yet Fix from $5,7502026-08-16 CRITICAL 9.9 CVE-2026-19959 A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup. This man… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.1 CVE-2026-74790 Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to e… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-73061 Scriban before 7.2.2 contains an access-modifier bypass vulnerability in TypedObjectAccessor that allows template code to write CLR object properties… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-73056 SiYuan kernel versions before 3.7.4 contain an improper restriction of excessive authentication attempts vulnerability in the CheckAuth() middleware.… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-72887 Net::OAuth::Client versions before 0.32 for Perl allow the service provider to silently downgrade OAuth 1.0a to OAuth 1.0 in get_request_token. Pass… Patch available Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-19349 Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass vi… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.3 CVE-2026-74251 Joomla Extension - phoca.cz - Unauthenticated SQL injection via attribute filter in Phoca Cart 5.0.0-6.1.6 - The a[] (attribute) and s[] (specificat… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2024-13784 The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and i… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.1 CVE-2026-19725 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.131 does not sanitise a value taken from an unauthenticated request before usin… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.1 CVE-2026-19714 The Simple JWT Login WordPress plugin before 3.6.8 does not validate the audience of the Google identity tokens it accepts, allowing unauthenticated… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.1 CVE-2026-18316 The Solace Extra plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check on the import_zip… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-18432 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.29.9. The vulnera… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-16098 The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 2.0.10 via the proSol_han… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.1 CVE-2026-14524 The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the proSol_fileDe… No fix yet Fix from $5,7502026-08-16 CRITICAL 9.8 CVE-2026-19924 A security vulnerability has been detected in Tenda AC10 16.03.10.09_multi_TDE01. This vulnerability affects the function R7WebsSecurityHandler of th… No fix yet Fix from $5,7502026-08-16 CRITICAL 10.0 CVE-2026-74764 Pandora contains a path traversal vulnerability in its TAR archive extraction functionality. When processing a submitted TAR archive, the extractor p… Patch available Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73053 SiYuan versions before v3.7.4 contain a cross-site scripting vulnerability in the unicode2Emoji function that fails to sanitize codepoint branch outp… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73052 SiYuan before v3.7.4 stores attribute-view field names without HTML escaping and interpolates them directly into option elements via innerHTML in the… No fix yet Fix from $5,7502026-08-15 CRITICAL 9.0 CVE-2026-73050 SiYuan versions before v3.7.4 fail to validate or escape the color field in attribute-view select options, allowing stored cross-site scripting throu… No fix yet Fix from $5,7502026-08-15