Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2026-66691 Unauthenticated Broken Access Control in Nokri <= 1.6.6 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-66478 Unauthenticated SQL Injection in Church Admin <= 5.1.1 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-66472 Unauthenticated SQL Injection in Everest Backup <= 2.3.12 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-66465 Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-66458 Unauthenticated SQL Injection in RealPress <= 1.1.2 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-66453 Unauthenticated Broken Authentication in Salon booking system <= 10.30.26 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-66446 Subscriber SQL Injection in If-So Dynamic Content Personalization <= 1.10 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-66436 Unauthenticated SQL Injection in Active Products Tables for WooCommerce <= 1.1.1 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-66424 Unauthenticated Privilege Escalation in SMS Alert Order Notifications <= 3.9.7 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-61969 Unauthenticated SQL Injection in Listdom <= 5.6.0 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-61967 Unauthenticated Privilege Escalation in miniorange otp verification <= 5.5.1 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-61966 Subscriber SQL Injection in WPJAM Basic <= 7.0.1 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 10.0 CVE-2026-61962 Unauthenticated Arbitrary Code Execution in WP BASE Booking <= 6.3.0 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-28185 Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-28149 Unauthenticated PHP Object Injection in Headless Single Sign On <= 1.6 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-28148 Unauthenticated Bypass Vulnerability in Headless Single Sign On <= 1.6 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-28142 Unauthenticated SQL Injection in Web Directory Free <= 1.7.13 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-28008 Unauthenticated Broken Authentication in OAuth Single Sign On – SSO (OAuth Client) <= 7.0.0 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-28001 Unauthenticated SQL Injection in WP Directory Kit <= 1.5.4 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 10.0 CVE-2026-27544 Unauthenticated Remote Code Execution (RCE) in QA Analytics <= 5.2.0.0 versions. No fix yet Fix from $2,3002026-08-13 CRITICAL 9.8 CVE-2026-49827 WebErpMesv2 is a Resource Management and Manufacturing execution system Web for industry. Versions 1.19 and prior allow any self-registered user to u… Patch available Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73602 Flowise before 3.1.3 contains a sandbox escape vulnerability in the vm2 JavaScript sandbox that allows authenticated users to execute arbitrary code … Patch available Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73601 Flowise versions before 3.1.3 contain a remote code execution vulnerability in the Custom MCP node when CUSTOM_MCP_PROTOCOL is set to stdio, allowing… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73487 Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inj… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73486 Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to e… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.0 CVE-2026-73485 Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Py… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.4 CVE-2026-73483 Flowise (packages flowise and flowise-components) in versions <= 3.1.2 contain a sandbox escape in the vm2/@flowiseai/nodevm JavaScript sandbox. An a… No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-59507 CWE-798: Use of Hard-coded Credentials CWE-200: Exposure of Sensitive Information to an Unauthorized Actor CWE-284: Improper Access Control No fix yet Fix from $2,3002026-08-13 CRITICAL 9.3 CVE-2026-59506 CWE-306: Missing Authentication for Critical Function No fix yet Fix from $2,3002026-08-13 CRITICAL 9.1 CVE-2026-59504 CWE-602: Client-Side Enforcement of Server-Side Security No fix yet Fix from $2,3002026-08-13