Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-19044 A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of the file src/index.ts of the… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2025-49506 APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potenti… Apr Util 1.6.4+ Fix from $1,9502026-08-06 CRITICAL 9.1 CVE-2026-64993 Dell RVTools versions prior to 4.8.1, contains an improper certificate validation vulnerability in the collector. A remote unauthenticated attacker c… Rvtools 4.8.1+ Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-5134 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Loca Software Informatics Technology Ltd. Co. C… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.3 CVE-2026-19041 A vulnerability has been found in MissionSquad mcp-api up to 1.11.8. The impacted element is the function this.packageService.installPackage of the f… Patch available Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19040 A flaw has been found in MissionSquad mcp-api up to 1.11.9. The affected element is an unknown function of the file src/services/dcrClients.ts. Execu… Patch available Fix from $1,6002026-08-06 MEDIUM 6.4 CVE-2026-18501 The UsersWP – Front-end login form, User Registration, User Profile & Members Directory plugin for WP plugin for WordPress is vulnerable to Stored Cr… Patch available Fix from $1,6002026-08-06 HIGH 8.3 CVE-2026-16731 OMICRON StationScout before version 3.05 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may … No fix yet Fix from $1,9502026-08-06 HIGH 8.7 CVE-2026-16315 OMICRON StationGuard before version 4.10 contains a cryptographic timing side-channel vulnerability in the backend authentication mechanism that may … No fix yet Fix from $1,9502026-08-06 CRITICAL 9.6 CVE-2026-12605 In Eclipse GlassFish versions 8.0.x before 8.0.4, CSRF + SSRF in DownloadServlet ContentSources leaks the admin `gfresttoken` to attacker-controlled … Glassfish 8.0.4+ Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-66733 Sonic 3 A.I.R. before commit 2492d18 contains an unbounded memory allocation vulnerability in ReceivedPacketCache::enqueuePacket() that allows unauth… Patch available Fix from $1,9502026-08-06 MEDIUM 5.9 CVE-2026-66732 Sonic 3 A.I.R. before commit 2492d18 contains a missing source address validation vulnerability in ConnectionManager where established connections ar… Patch available Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-65551 Missing Authorization vulnerability in Soflyy Breakdance allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-19039 A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted is the function ssh_exec of t… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19038 A security vulnerability has been detected in MonomythDevelopment la-forge-mcp 1.0.0. This issue affects the function screenshotElement of the file s… Patch available Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-19036 A security flaw has been discovered in Shibby Tomato 1.28.0000. This affects the function sub_40F88C of the file /tmp/ppp/wanoptions. The manipulatio… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-0673 The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to, and including, 8.3.15 via t… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-8166 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Logo Software Industry and Trade Inc. E-Logo Pu… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-68481 In Apache CXF's DefaultEncryptingOAuthDataProvider, revoked access tokens still decrypt successfully, and TokenIntrospectionService reports active:tr… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-68079 In Apache CXF's DefaultEncryptingCodeDataProvider, a captured authorization code can be redeemed an unlimited number of times due to a flaw in the im… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-65583 Apache CXF’s OIDC relying-party token validation could accept self-issued ID tokens without enforcing required claim checks (issuer/subject/audience/… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-63687 Apache CXF's JwtRequestCodeFilter copies all claims from a signed request JWT into the authorization parameter map without excluding security-sensiti… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 CRITICAL 9.1 CVE-2026-61466 In Apache CXF's OAuth2 Dynamic Client Registration endpoint, the authorization server accepts and stores the `scope` value supplied in the client reg… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06 MEDIUM 6.4 CVE-2026-5391 The LatePoint plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'btn_wrapper_classes' attribute of the 'latepoint_resources' … No fix yet Fix from $1,6002026-08-06 MEDIUM 6.4 CVE-2026-5158 The Post Grid Gutenberg Blocks for News, Magazines, Blog Websites – PostX plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '… No fix yet Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-57818 A race condition in JCacheCodeDataProvider allows an attacker to redeem a single authorization code multiple times via concurrent requests, resulting… Cxf 3.6.12 / 4.1.8+ Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-19035 A vulnerability was identified in Shibby Tomato 1.28.0000. Affected by this issue is the function new_qoslimit_start of the file /etc/qoslimit. The m… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-11983 The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.8.16 du… No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2025-15028 The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Si… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-66909 Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in pla… Cxf 3.6.12 / 4.1.8+ Fix from $2,3002026-08-06