Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.0 CVE-2026-53996 NetBSD's hdaudio(4) driver in sys/dev/hdaudio/hdaudio.c contains a missing access control vulnerability that allows unprivileged local attackers to i… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-47226 Admidio is an open-source user management solution. Prior to version 5.0.10, an authenticated Admidio member with upload rights on any one folder can… No fix yet Fix from $4,0002026-08-12 CRITICAL 9.8 CVE-2026-26035 An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4… No fix yet Fix from $5,7502026-08-12 MEDIUM 5.4 CVE-2026-70560 Ultimate POS (Stock Management & Point of Sale) contains a stored cross-site scripting vulnerability that allows low-privileged authenticated attacke… No fix yet Fix from $4,0002026-08-12 HIGH 8.1 CVE-2026-70465 A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClien… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.3 CVE-2026-17008 The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status in its PayPal IPN handler and … No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-16990 The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-side and trusts a client-suppli… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-16747 The Kirki WordPress plugin before 6.2.1 does not properly authorise its front-end form submission REST routes and passes attacker-controlled input th… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-16621 The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succeeded before completing an orde… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-15213 The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-transfer settlement callback:… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-15045 The Wallet System for WooCommerce WordPress plugin before 2.7.10 does not validate a user-supplied wallet amount against the customer's actual stored… No fix yet Fix from $4,0002026-08-12 HIGH 8.8 CVE-2026-11325 Description Cloudflare was recently notified by external researchers of vulnerabilities in this archived repository, including a remote code execu… No fix yet Fix from $4,9002026-08-12 MEDIUM 6.5 CVE-2026-68868 The Google Cloud Secret Manager secrets backend in Apache Airflow's Google provider never applied the team scope when resolving Connections and Varia… Apache Airflow Providers Google 22.3.0+ Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-67284 Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.3 - Authenticated users could perform vario… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.1 CVE-2026-64955 When Microsoft Excel imports a CSV file, it executes cells beginning with certain characters as formulas, giving such CSV files arbitrary execution. … No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-64952 The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLLECT_CLIENT (usually assigned … No fix yet Fix from $4,0002026-08-12 MEDIUM 5.9 CVE-2026-18663 A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() function frees the parsed controls array on the Session Tracking critical-control… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.9 CVE-2026-67283 Joomla Extension - tabaoca.org - Improper ACL implementation allows file operations in Cotton Cloud < 2.0.2 - Unauthenticated users could perform var… No fix yet Fix from $4,0002026-08-12 CRITICAL 10.0 CVE-2026-67282 Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute arbitrary code … No fix yet Fix from $5,7502026-08-12 HIGH 7.5 CVE-2026-19566 Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion and malformed set ranges via unbounded IPv6 prefix lengths. The _encode method … Patch available Fix from $4,9002026-08-12 HIGH 8.2 CVE-2026-19426 POS System developed by FitSoft has a Missing Authentication vulnerability. Unauthenticated remote attackers can directly access and operate the syst… No fix yet Fix from $4,9002026-08-12 HIGH 7.5 CVE-2025-41770 An unauthenticated denial-of-service vulnerability in the device's PLCnext Engineer communication interface allow an remote attacker to interrupt acc… No fix yet Fix from $4,9002026-08-12 CRITICAL 9.8 CVE-2025-41769 The device's PROFINET service is affected by a buffer overflow vulnerability that exists in the default configuration. An unauthenticated remote atta… No fix yet Fix from $5,7502026-08-12 CRITICAL 9.3 CVE-2026-66659 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Essekia Tablesome Table allows Blind SQL Inject… No fix yet Fix from $5,7502026-08-12 HIGH 8.1 CVE-2026-19594 Insufficient input sanitization in Snowflake Python API (`snowflake.core`) versions prior to 1.13.0 allowed confused-deputy privilege escalation thro… No fix yet Fix from $4,9002026-08-12 MEDIUM 5.4 CVE-2026-19217 The Royal Addons for Elementor WordPress plugin before 1.7.1065 does not validate a widget setting used to build an HTML tag before outputting it, w… No fix yet Fix from $4,0002026-08-12 MEDIUM 5.3 CVE-2026-19073 The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one of its REST API endpoints, and… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.4 CVE-2026-19050 The ProSolution WP Client WordPress plugin before 2.0.9 does not validate a user-supplied URL, and does not check the capability or nonce of the requ… No fix yet Fix from $4,0002026-08-12 MEDIUM 6.5 CVE-2026-18943 The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allowing users with a role as low … No fix yet Fix from $4,0002026-08-12 HIGH 7.5 CVE-2026-18789 The Ezoic WordPress plugin before 2.23.1 does not properly restrict access to some of its content export functionality, allowing unauthenticated atta… No fix yet Fix from $4,9002026-08-12