Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-49429 The ZFS_IOC_USERSPACE_MANY ioctl, used by zfs-userspace(8), truncated a 64-bit output buffer size to a 32-bit integer for the kernel allocation, but … Fix unknown Fix from $4,9002026-08-19 HIGH 8.4 CVE-2026-49428 Certain system calls, such open(2) with the O_TRUNC flag set, and fspacectl(2), could incorrectly free memory in largepage objects. These operations… Fix unknown Fix from $4,9002026-08-19 HIGH 8.4 CVE-2026-49422 The RACK setsockopt(2) handler drops the connection lock in order to copy option data from userspace, then reacquires the lock. After reacquiring, i… Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-49420 The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewritten data fit in the buffer,… Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-19842 The SAML Single Sign On WordPress plugin before 5.4.7 does not verify the signature of a SAML response before storing the certificate it carries, an… Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.4 CVE-2026-19782 The WPS Bidouille WordPress plugin before 1.33.5 does not have proper authorisation checks in an AJAX action, allowing any authenticated user, such a… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-19709 The Membership For WooCommerce WordPress plugin before 3.1.2 does not check that an API consumer secret has actually been generated before comparing … Fix unknown Fix from $4,0002026-08-19 MEDIUM 6.5 CVE-2026-19417 The KiviCare WordPress plugin before 4.5.4 does not verify that the requesting user is entitled to the media file being served, allowing authenticat… Fix unknown Fix from $4,0002026-08-19 HIGH 7.1 CVE-2026-19056 The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one … Fix unknown Fix from $4,9002026-08-19 HIGH 7.1 CVE-2026-19055 The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes … Fix unknown Fix from $4,9002026-08-19 CRITICAL 9.0 CVE-2026-18937 The Broken Link Checker WordPress plugin before 2.4.12 does not limit which query variables it accepts from user input on sites using plain permalink… Fix unknown Fix from $5,7502026-08-19 MEDIUM 5.3 CVE-2026-18779 The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-18778 The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-18777 The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in one of its AJAX actions, allowing unauthenticated users to… Fix unknown Fix from $4,0002026-08-19 CRITICAL 9.8 CVE-2026-18776 The TrueBooker WordPress plugin before 1.2.7 does not have proper authorisation checks in some of its AJAX actions, allowing unauthenticated users t… Fix unknown Fix from $5,7502026-08-19 MEDIUM 5.4 CVE-2026-18466 The WP Maps WordPress plugin before 4.9.8 does not perform a capability check, nor validate a nonce, in one of its AJAX actions, allowing users with… Fix unknown Fix from $4,0002026-08-19 MEDIUM 5.3 CVE-2026-18231 The WP Directory Kit WordPress plugin before 1.5.7 does not perform any authorization check on one of its public AJAX actions and returns unfiltered … Fix unknown Fix from $4,0002026-08-19 MEDIUM 6.8 CVE-2026-18202 The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising the file contents, allowing us… Fix unknown Fix from $4,0002026-08-19 CRITICAL 10.0 CVE-2026-18051 The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthentic… Fix unknown Fix from $5,7502026-08-19 CRITICAL 9.8 CVE-2026-18031 The TabaPay Gateway WordPress plugin through 1.4.0 does not validate the payment callback before establishing a session for the account associated wi… Fix unknown Fix from $5,7502026-08-19 HIGH 7.2 CVE-2026-17565 The Animation Addons for Elementor WordPress plugin before 2.7.2 does not validate a user-supplied value before using it to build the host of a serv… Fix unknown Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-16950 The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowing u… Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-16617 The Simple File List WordPress plugin through 6.3.11 does not properly sanitise and escape a file's description before outputting it on the public fi… Fix unknown Fix from $4,9002026-08-19 HIGH 8.6 CVE-2026-16616 The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachable by unauthenticated users, a… Fix unknown Fix from $4,9002026-08-19 HIGH 7.1 CVE-2026-16570 The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on on… Fix unknown Fix from $4,9002026-08-19 MEDIUM 5.3 CVE-2026-16058 The YayCurrency WordPress plugin before 3.3.5 does not perform any capability or ownership check on several of its multi-vendor integration handlers… Fix unknown Fix from $4,0002026-08-19 MEDIUM 6.8 CVE-2026-15253 The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting it in an HTML attribute in t… Fix unknown Fix from $4,0002026-08-19 HIGH 7.5 CVE-2026-14861 The User Verification by PickPlugins WordPress plugin through 2.0.47 does not verify that a request to resend a verification email is authorized to a… Fix unknown Fix from $4,9002026-08-19 HIGH 8.8 CVE-2026-14334 The Booking calendar, Appointment Booking System WordPress plugin through 3.2.36 does not properly sanitize uploaded SVG files, allowing unauthentica… Fix unknown Fix from $4,9002026-08-19 MEDIUM 6.5 CVE-2026-13175 The Eventin WordPress plugin before 4.1.21 does not verify ownership before allowing schedule records to be modified or deleted, allowing users with… Fix unknown Fix from $4,0002026-08-19