Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.3 CVE-2026-66649 Unauthenticated SQL Injection in Directory Pro <= 2.5.8 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-66609 Unauthenticated SQL Injection in TheGem (Elementor) <= 5.12.3 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-66600 Author Arbitrary File Upload in Media LIbrary Assistant <= 3.39 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-66593 Unauthenticated SQL Injection in Security & Malware scan by CleanTalk <= 2.184 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2026-66592 Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and bbPress <= 4.7.11 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-66583 Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2025-15689 Unauthenticated Privilege Escalation in Capella <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.3 CVE-2025-15688 Unauthenticated SQL Injection in Capella <= 2.5.5 versions. No fix yet Fix from $5,7502026-08-20 CRITICAL 9.1 CVE-2026-13097 A privilege escalation flaw was found in FreeIPA. The uniqueness constraint enforced on Kerberos principal name attributes in the 389-ds directory se… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.6 CVE-2026-11861 A flaw was found in FreeIPA. When a trust relationship is configured between FreeIPA and Active Directory, Active Directory users can bypass authenti… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-14950 An unauthenticated remote attacker in possession of a valid session identifier is able to continue using the session after it should have expired. Th… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-75860 The JSON Options WordPress plugin through 0.0.4 does not have any capability check or nonce verification on one of its actions, which runs on every r… No fix yet Fix from $5,7502026-08-20 CRITICAL 9.8 CVE-2026-76850 LMDeploy deserializes disaggregated-serving peer messages with pickle. The handle_zmq_recv coroutine in lmdeploy/pytorch/disagg/conn/engine_conn.py r… Patch available Fix from $5,7502026-08-19 CRITICAL 9.9 CVE-2026-76590 A vulnerability was identified in TRENDnet TEW-755AP up to 20260702. Affected by this issue is some unknown functionality of the file /cgi-bin/wan.cg… No fix yet Fix from $5,7502026-08-19 CRITICAL 9.9 CVE-2026-76589 A vulnerability was found in TRENDnet TEW-755AP up to 20260702. Affected is the function FUN_401000 of the file /sbin/mycli. The manipulation of the … No fix yet Fix from $5,7502026-08-19 CRITICAL 9.1 CVE-2026-76404 In Splunk MCP Server app versions below 1.2.1, a user who holds the "admin" Splunk role could execute arbitrary commands on the underlying operating … No fix yet Fix from $5,7502026-08-19 CRITICAL 9.4 CVE-2026-76312 In Splunk Enterprise versions below 10.4.1, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who can read the Hypertext Markup Language (HTML) sou… Splunk 9.4.14 / 10.0.9+ Fix from $5,7502026-08-19 CRITICAL 9.4 CVE-2026-76311 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the d… Splunk 9.4.14 / 10.0.9+ Fix from $5,7502026-08-19 CRITICAL 9.4 CVE-2026-76310 In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report token could download the a… Splunk 9.4.14 / 10.0.9+ Fix from $5,7502026-08-19 CRITICAL 9.9 CVE-2026-76584 A security flaw has been discovered in TRENDnet TV-IP751WIC 11.03.03. Affected by this issue is some unknown functionality of the file /cgi-bin/admin… No fix yet Fix from $5,7502026-08-19 CRITICAL 9.1 CVE-2026-75595 Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Fina and 4.2.17.Final, io.netty.handler.ssl.SslClientHelloHand… Patch available Fix from $5,7502026-08-19 CRITICAL 9.6 CVE-2026-53548 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.6.1, the GET /host/db/host/:… Patch available Fix from $5,7502026-08-19 CRITICAL 9.6 CVE-2026-53546 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the terminal WebSocket … Patch available Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-53545 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to 2.3.2, the DELETE /ssh/tunnel/… Patch available Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-63722 ICEcoder 8.1 contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands b… No fix yet Fix from $5,7502026-08-19 CRITICAL 9.9 CVE-2026-55089 Etherpad is a real-time collaborative editor. From 2.1.0 until 3.1.0, Etherpad's src/node/handler/APIHandler.ts authorizes requests to /api/2/* in th… Patch available Fix from $5,7502026-08-19 CRITICAL 9.6 CVE-2026-55085 Etherpad is a real-time collaborative editor. Prior to 3.3.1, result.appendSpan in src/static/js/domline.ts interpolates the start attribute of a num… Patch available Fix from $5,7502026-08-19 CRITICAL 10.0 CVE-2026-22306 Download of code without integrity check, inclusion of functionality from untrusted control sphere, and cleartext transmission of sensitive informat… No fix yet Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-16919 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper validation of network-supplied … Aix 4.1.0.50 / 4.1.1.30+ Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-16917 IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer overflow. Vios 4.1.0.50 / 4.1.1.30+ Fix from $5,7502026-08-19