Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-3835 The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-19088 The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentication endpoints against CSRF, … No fix yet Fix from $4,0002026-08-13 HIGH 8.2 CVE-2026-18945 The WP Helper Premium WordPress plugin before 4.7.6 does not verify the order key when rendering its custom order confirmation page or when handling … No fix yet Fix from $4,9002026-08-13 HIGH 7.5 CVE-2026-13610 The KiviCare WordPress plugin before 4.5.2 does not restrict the roles assignable through its unauthenticated registration endpoint, allowing unauth… No fix yet Fix from $4,9002026-08-13 MEDIUM 5.3 CVE-2026-13328 The Food Menu WordPress plugin before 6.0.2 does not perform any capability or ownership check on its reservation-status update action, which is als… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-14182 The Customer Email Verification for WooCommerce WordPress plugin before 3.2.6 does not correctly validate the email-verification activation code, rel… No fix yet Fix from $5,7502026-08-13 MEDIUM 5.4 CVE-2026-72506 VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly specified destination in a commun… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.4 CVE-2026-19135 A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authenticated user can submit a crafte… Patch available Fix from $4,0002026-08-13 MEDIUM 6.5 CVE-2026-18728 A flaw was found in open-iscsi. An integer underflow vulnerability in the `iscsiuio` component, specifically during IPv4 Dynamic Host Configuration P… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.9 CVE-2026-0299 Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHOR… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.2 CVE-2026-0298 An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ … No fix yet Fix from $4,0002026-08-13 MEDIUM 5.2 CVE-2026-0297 A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gatew… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.0 CVE-2026-0294 A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to exe… No fix yet Fix from $4,0002026-08-13 MEDIUM 5.6 CVE-2026-0293 A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tampe… No fix yet Fix from $4,0002026-08-13 MEDIUM 6.3 CVE-2026-50544 NortheBridge/luminalshine is a Sunshine-compatible game stream host for Moonlight. Prior to version 26.05.0-rc4, a latent gap exists on a default ins… No fix yet Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-49819 UpSnap is a wake on lan web app. Versions 4.4.1 through 5.3.5 are vulnerable to a missing-authentication / privilege-escalation chain in `pb.HandlerI… No fix yet Fix from $5,7502026-08-13 HIGH 8.8 CVE-2026-49473 @cedar-policy/authorization-for-expressjs is an open-source Express.js middleware that integrates Cedar authorization into Express applications by ma… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.9 CVE-2026-46688 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, an unauthenticated request can … No fix yet Fix from $4,0002026-08-13 HIGH 8.7 CVE-2026-46382 The Meeting Room Booking System (MRBS) is a PHP-based application for booking meeting rooms. Prior to version 1.12.2, a user-supplied private/local U… No fix yet Fix from $4,9002026-08-13 MEDIUM 6.1 CVE-2026-17431 PDF::WebKit versions through 1.2 for Perl allow OS command injection via a 2-arg open() of the output path in to_pdf and of stylesheet paths in _styl… Patch available Fix from $4,0002026-08-13 CRITICAL 9.8 CVE-2026-16770 PDF::WebKit versions through 1.2 for Perl allow argument injection into wkhtmltopdf via meta tags in the source document. For an HTML string or file… Patch available Fix from $5,7502026-08-13 MEDIUM 6.8 CVE-2026-71194 In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOTIFY requests. When two zones … No fix yet Fix from $4,0002026-08-12 CRITICAL 9.6 CVE-2026-71193 In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, _is_superzone, and the duplicate-zone DB constraint) are scoped to the targe… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.6 CVE-2026-49481 UpSnap is a wake on lan web app. Versions prior to 5.4.0 have an OS command injection vulnerability in the UpSnap’s device management functionality d… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.5 CVE-2026-47718 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. When `secureEnabled=true`, FUXA `1.3.0-2773` still allows guest and invalid… No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-47717 FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In fuxa-server version 1.3.0, the GET /api/project endpoint exposes sensiti… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-15141 The web interface of the affected device relies on the HTTP referrer header as part of request validation.  Requests containing empty Referer value, … No fix yet Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-73519 WolfStack before 25.9.2 contains a hard-coded cluster-authentication secret compiled into every build and published as a constant in src/auth/mod.rs,… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.1 CVE-2026-73501 kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144.0, ValidationHandler.Load() in openapi3filter/validation_handler.go silently r… Patch available Fix from $5,7502026-08-12 HIGH 8.7 CVE-2026-73500 etcd is a distributed key-value store for the data of a distributed system. Prior to versions 3.5.33, 3.6.14, and 3.7.1, a network attacker who can r… Patch available Fix from $4,9002026-08-12