Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-16578 The Admin Safety Guard — Login Security, Limit Logins, 2FA & Brute Force Protection WordPress plugin before 1.4.0 does not perform any capability che… No fix yet Fix from $1,9502026-08-08 MEDIUM 6.5 CVE-2026-16562 The WP Statistics WordPress plugin before 14.16.10 does not perform a capability check on a set of dashboard analytics AJAX handlers, relying only o… No fix yet Fix from $1,6002026-08-08 MEDIUM 5.4 CVE-2026-16558 The YMC Filter WordPress plugin before 3.12.8 does not sanitize and escape a layout builder setting before outputting it on a public endpoint, and do… No fix yet Fix from $1,6002026-08-08 MEDIUM 6.1 CVE-2026-16535 The Link Library WordPress plugin before 7.9.4 does not sanitise and escape a parameter before reflecting it back in a response, allowing unauthentic… No fix yet Fix from $1,6002026-08-08 MEDIUM 5.3 CVE-2026-16282 The Appointment Hour Booking WordPress plugin before 1.5.88 does not validate a client-supplied booking price against the server-side configured ser… No fix yet Fix from $1,6002026-08-08 HIGH 8.1 CVE-2026-16267 The Newsletters WordPress plugin before 4.16 does not restrict the classes allowed when unserialising a value taken from a public form submission, al… No fix yet Fix from $1,9502026-08-08 CRITICAL 9.8 CVE-2026-14526 The AI Copilot – Content Generator plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.5.6. This is du… No fix yet Fix from $2,3002026-08-08 MEDIUM 6.4 CVE-2026-18988 The Easy Accordion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'accordionTitleTag' block attribute in versions up to, a… No fix yet Fix from $1,6002026-08-08 HIGH 8.7 CVE-2026-13505 In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 (1.0.X series), 2.0.2 (2.0.X series) and 2.1.3 (2.1.X series), sensitive key material … No fix yet Fix from $1,9502026-08-08 HIGH 8.7 CVE-2026-8798 In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions … No fix yet Fix from $1,9502026-08-08 HIGH 7.5 CVE-2026-52880 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions from 1.7.14 through 1.7.17 are vulnerable to a remotely triggerable de… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-52879 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions 1.7.14 through 1.7.17, the direct-message ingress handler spawns a … No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-52878 Klever-Go is the Go implementation of the Klever blockchain protocol. Versions 1.7.14 through 1.7.17 are vulnerable to a nil-pointer panic triggered … No fix yet Fix from $1,9502026-08-07 MEDIUM 5.9 CVE-2026-49343 Klever-Go is the Go implementation of the Klever blockchain protocol. In versions prior to 1.7.18, the account-data trie syncers are vulnerable to a … No fix yet Fix from $1,6002026-08-07 MEDIUM 5.4 CVE-2026-48122 Ruby LSP is an implementation of the language server protocol for Ruby. Several workspace-level settings in the Ruby LSP VS Code extension prior to v… No fix yet Fix from $1,6002026-08-07 HIGH 8.6 CVE-2026-48120 Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be exploited by malicious backup… Patch available Fix from $1,9502026-08-07 MEDIUM 5.9 CVE-2026-48047 XWiki Platform WebJars API is a package for XWiki, a generic wiki platform. Starting with version 9.6-rc-1 and prior to versions 16.10.17, 17.4.9, an… Patch available Fix from $1,6002026-08-07 HIGH 8.7 CVE-2026-48026 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.8… No fix yet Fix from $1,9502026-08-07 HIGH 7.5 CVE-2026-47249 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.18, the P2P resolver request handling logic is vulnerable to hash-… No fix yet Fix from $1,9502026-08-07 MEDIUM 6.5 CVE-2026-47127 Ghostfolio is an open source wealth management software. Prior to version 3.4.0, Ghostfolio's Stripe checkout success-URL handler at `GET /api/v1/sub… Patch available Fix from $1,6002026-08-07 CRITICAL 9.6 CVE-2026-46409 OpenYak is a local-first agent runtime for reliable tool-using models, with a desktop workspace built on top. Prior to version 1.1.3, the OpenYak des… No fix yet Fix from $2,3002026-08-07 MEDIUM 5.7 CVE-2026-64676 Kata Containers is an open source implementation of lightweight Virtual Machines (VMs) that perform like containers. In versions prior to 4.0.0, the … No fix yet Fix from $1,6002026-08-07 HIGH 7.1 CVE-2026-58262 Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.20, header signature verification counts the unused padding bits o… Patch available Fix from $1,9502026-08-07 CRITICAL 9.1 CVE-2026-48170 `scim-patch`, a library to perform SCIM patch, prior to version 0.9.1 performs prototype pollution when applying a SCIM PATCH operation whose `value`… Patch available Fix from $2,3002026-08-07 HIGH 8.8 CVE-2026-48169 PraisonAI is a multi-agent teams system. Versions prior to 0.1.4 of the PraisonAI Platform API have two authorization failures that together break wo… No fix yet Fix from $1,9502026-08-07 CRITICAL 9.2 CVE-2026-47243 Kata Containers is an open source project focusing on a standard implementation of lightweight Virtual Machines (VMs) that perform like containers. P… No fix yet Fix from $2,3002026-08-07 MEDIUM 5.3 CVE-2026-46405 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, in OpenBao's Kerberos auth method on the `GET` handler, o… Patch available Fix from $1,6002026-08-07 HIGH 7.1 CVE-2026-45808 OpenBao is an open source identity-based secrets management system. Prior to version 2.5.4, OpenBao's namespaces provide multi-tenant separation. A t… Patch available Fix from $1,9502026-08-07 MEDIUM 6.6 CVE-2026-11743 The SF32LB MPI QSPI NOR flash driver (drivers/flash/flash_sf32lb_mpi_qspi_nor.c) validated the flash offset and length on its read and write paths wi… Patch available Fix from $1,6002026-08-07 MEDIUM 6.8 CVE-2026-9031 An input validation vulnerability exists in the HTTP-WRITEOEM handler due to insufficient validation of user-supplied data before it is processed by … No fix yet Fix from $1,6002026-08-07