Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-18649 A flaw was found in the GStreamer gst-plugins-good package. The rtph264depay and rtph265depay RTP depayloader elements do not enforce a maximum size … No fix yet Fix from $1,9502026-08-06 HIGH 8.5 CVE-2026-18597 The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could t… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.4 CVE-2025-15039 The Conditional Authentication (Adaptive Authentication) script does not correctly enforce the completion of all required authentication steps when a… Api Control Plane 1.4.0.137 / 1.4.0.143+ Fix from $2,3002026-08-06 MEDIUM 5.4 CVE-2025-13394 The Ajax processor within the Carbon console fails to adequately protect state-changing operations from Cross-Site Request Forgery (CSRF) attacks. Sp… Api Control Plane 2.0.0.401 / 2.0.0.421+ Fix from $1,6002026-08-06 HIGH 7.5 CVE-2024-6832 The account locking mechanism fails to trigger when secondary user stores are inaccessible. The software does not maintain a consistent state for acc… Api Control Plane No fix yet Fix from $1,9502026-08-06 MEDIUM 5.8 CVE-2024-10302 The user self-signup flow in multiple WSO2 products fails to adequately validate user-supplied input. This weakness allows arbitrary unvalidated data… Api Control Plane No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19007 A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. This vulnerability affects the function isApprovedElevatedSender of the file src/a… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19006 A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affects an unknown part of the file src/agents/bash-tools.exec.ts of the component Gg… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-19005 A vulnerability was detected in nanocoai NanoClaw up to 2.0.64. Affected is the function handleCreateAgent of the file src/modules/agent-to-agent/cre… No fix yet Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-18967 A flaw was found in the SAML broker component of Keycloak, an identity and access management solution. When configured as a SAML broker using the IdP… Build Of Keycloak No fix yet Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-18510 The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Comment C… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.4 CVE-2026-18400 The Slider, Gallery, and Carousel by MetaSlider – Image Slider, Video Slider plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'd… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-18395 The Child Pages Card WordPress plugin before 1.09 does not sanitise and escape some of its shortcode attributes before outputting them back in a page… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-18050 The Events Manager WordPress plugin before 7.4 does not perform any authorization check on a REST route that serves temporarily stored file uploads,… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-16954 The AI Engine WordPress plugin before 3.6.4 does not redact secret configuration values before exposing them in an admin page's inline script data, … No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-16734 The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.2 does not verify that the caller owns the Stripe payment intent referenced by t… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.4 CVE-2026-16537 The Slick Slider WordPress plugin before 0.5.3 does not sanitize and escape a shortcode attribute value before outputting it in an HTML attribute, al… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-16290 The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member list, and registers the hand… No fix yet Fix from $1,6002026-08-06 HIGH 8.2 CVE-2026-16268 The Newsletters WordPress plugin before 4.16 does not authenticate or validate a bounce-processing request before fetching a user-supplied URL on the… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.5 CVE-2026-16065 The Welcart e-Commerce WordPress plugin before 2.11.32 does not properly sanitise a value taken from an imported CSV file before using it in a SQL st… No fix yet Fix from $1,6002026-08-06 CRITICAL 9.1 CVE-2026-16054 The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.8 does not prevent unauthenticated users from obtaining a valid no… No fix yet Fix from $2,3002026-08-06 HIGH 8.2 CVE-2026-14829 The Checkimate — WooCommerce Checkout, Abandoned Cart Recovery & Order Bumps WordPress plugin through 1.0.13 does not properly restrict access to its… No fix yet Fix from $1,9502026-08-06 MEDIUM 5.3 CVE-2026-14547 The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict the recipient routing of its p… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14314 The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment belongs to the order referenced … No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14313 PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-bacs-receipt-upload-for-wooco… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-14240 The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its publicly accessible directory wi… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.5 CVE-2026-14204 The Google Authenticator WordPress plugin before 0.56 does not verify a CSRF nonce when saving its two-factor setup, allowing attackers to trick a lo… No fix yet Fix from $1,6002026-08-06 MEDIUM 5.4 CVE-2026-13703 The SEO Redirection Plugin WordPress plugin before 9.19 does not perform a capability check in one of its authenticated AJAX actions, allowing any l… No fix yet Fix from $1,6002026-08-06 HIGH 7.5 CVE-2026-13154 The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not verify that an attacker-supplied post type is publicly viewable before queryin… No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-13153 The Gutenberg Essential Blocks WordPress plugin before 6.4.0 does not restrict access to one of its public REST routes and over-fetches a non-public… No fix yet Fix from $1,9502026-08-06