Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2026-19347 A vulnerability was identified in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /viewdoctor.php… No fix yet Fix from $1,6002026-08-09 HIGH 8.8 CVE-2026-19346 A vulnerability was determined in Tenda CH22 1.0.0.1. This vulnerability affects the function formCertListInfo of the file /goform/CertListInfo. This… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.5 CVE-2026-19345 A vulnerability was found in code-projects Task Management System 1.0. This affects an unknown part of the file /user/UpdateTaskStatus.php. The manip… No fix yet Fix from $1,6002026-08-09 HIGH 7.3 CVE-2026-19344 A vulnerability has been found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/co… No fix yet Fix from $1,9502026-08-09 HIGH 7.3 CVE-2026-19343 A flaw has been found in code-projects Task Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/Admi… No fix yet Fix from $1,9502026-08-09 HIGH 7.3 CVE-2026-19342 A vulnerability was detected in code-projects Task Management System 1.0. Affected is an unknown function of the file /index.php of the component Log… No fix yet Fix from $1,9502026-08-09 HIGH 8.8 CVE-2026-19341 A security vulnerability has been detected in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/pptpSrvGlobal… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.3 CVE-2026-19340 A weakness has been identified in anubissbe ProjectHub-Mcp up to 5.0.0. This affects an unknown function of the file backend-fix/complete_backend.js … No fix yet Fix from $1,6002026-08-09 MEDIUM 6.3 CVE-2026-19339 A security flaw has been discovered in aliyun alibabacloud-dataworks-mcp-server up to 1.0.43. The impacted element is the function ReadResourceReques… No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19338 A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processGenerateRequest of the file mc… No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19337 A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/index.ts of the component rea… Patch available Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19336 A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.createApproval of the file src/to… Patch available Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19335 A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function getSkillVersionsDir of the fi… No fix yet Fix from $1,6002026-08-09 MEDIUM 6.5 CVE-2026-18603 The PiWeb Cancel order / Refund request for WooCommerce WordPress plugin before 1.3.4.34 does not have authorization or ownership checks when adding … No fix yet Fix from $1,6002026-08-09 CRITICAL 9.1 CVE-2026-18473 The WP Directory Kit WordPress plugin before 1.5.5 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a… No fix yet Fix from $2,3002026-08-09 MEDIUM 6.5 CVE-2026-18465 The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica… No fix yet Fix from $1,6002026-08-09 HIGH 7.5 CVE-2026-18464 The WP MAPS PRO WordPress plugin before 6.1.3 does not perform a capability check in one of its AJAX actions, which is also available to unauthentica… No fix yet Fix from $1,9502026-08-09 HIGH 7.5 CVE-2026-18357 The WPC Order Tip for WooCommerce WordPress plugin before 3.3.1 does not perform authorisation or nonce checks in one of its reporting features, allo… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.5 CVE-2026-18037 The Create WordPress plugin before 2.5.4 does not perform an authorization check before rendering content over one of its public REST API routes, and… No fix yet Fix from $1,6002026-08-09 HIGH 8.6 CVE-2026-17044 The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading t… No fix yet Fix from $1,9502026-08-09 HIGH 7.5 CVE-2026-18032 The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the … No fix yet Fix from $1,9502026-08-09 MEDIUM 5.3 CVE-2026-17014 The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not perform any capability or nonce check on one of its public REST endpoint actions,… No fix yet Fix from $1,6002026-08-09 HIGH 8.1 CVE-2026-17017 The CubeWP Framework WordPress plugin before 1.1.31 does not properly sanitize and escape a parameter before using it in a SQL statement through an A… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.5 CVE-2026-16992 The Create WordPress plugin before 2.5.4 does not perform an authorization check before returning content over one of its REST API routes, and that r… No fix yet Fix from $1,6002026-08-09 HIGH 7.5 CVE-2026-16988 The GeoDirectory WordPress plugin before 2.8.169 does not perform any authorization check when returning map marker data for a single requested list… No fix yet Fix from $1,9502026-08-09 MEDIUM 6.1 CVE-2026-16032 The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before stori… No fix yet Fix from $1,6002026-08-09 CRITICAL 9.8 CVE-2026-15038 The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remot… No fix yet Fix from $2,3002026-08-09 MEDIUM 5.3 CVE-2026-19334 A flaw has been found in NightTrek Ollama-mcp up to 80cf2e17cfc144963a475b619093a2d13c13dbc9. This affects an unknown part of the file src/index.ts. … No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19333 A vulnerability was detected in NightTrek Supabase-MCP cc994ab2d2a36b0af6ee7c7f3e6ce8e08cda2170/db03237d92f7dc2f0da0d70a87dba84ebcde5b66. Affected by… No fix yet Fix from $1,6002026-08-09 MEDIUM 5.3 CVE-2026-19332 A security vulnerability has been detected in NellyW8 MCP4EDA 1.0.0. Affected by this vulnerability is an unknown functionality of the component run_… No fix yet Fix from $1,6002026-08-09