Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-12713 The WPCargo Track & Trace WordPress plugin before 8.0.4 does not properly sanitise and escape a parameter before using it in a SQL statement, allowin… No fix yet Fix from $2,3002026-08-06 MEDIUM 6.1 CVE-2026-11588 The EONSR AEO Agent WordPress plugin through 3.7.9 does not perform any authorisation check on one of its REST API routes and disables HTML sanitisat… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.1 CVE-2025-15678 The Nexter Blocks WordPress plugin before 5.0.2 does not sanitize uploaded SVG files and allows SVG uploads for any user able to upload files (Autho… No fix yet Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-19000 A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component An… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-18998 A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.t… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18997 A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/… No fix yet Fix from $1,6002026-08-06 HIGH 8.1 CVE-2026-15459 The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet conn… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-18996 A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCo… No fix yet Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18993 A vulnerability was detected in NousResearch hermes-agent up to 0.16.0. Affected by this issue is some unknown functionality of the file hermes-agent… Patch available Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18992 A vulnerability was detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools of the file agent/evolution/exec… No fix yet Fix from $1,6002026-08-06 HIGH 7.2 CVE-2026-18325 The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Forged … No fix yet Fix from $1,9502026-08-06 HIGH 7.2 CVE-2026-16636 The FluentSMTP – WP SMTP Plugin with Amazon SES, SendGrid, MailGun, Postmark, Google and Any SMTP Provider plugin for WordPress is vulnerable to Stor… No fix yet Fix from $1,9502026-08-06 HIGH 8.8 CVE-2026-15991 The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in … No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-18991 A security vulnerability has been detected in nanocoai NanoClaw up to 2.0.64. This affects an unknown part of the file container/agent-runner/src/mcp… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-18990 A vulnerability was detected in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts of the component API Status Ro… No fix yet Fix from $1,9502026-08-06 MEDIUM 6.3 CVE-2026-18980 A vulnerability was identified in nearai ironclaw up to 0.29.1. Affected is the function classify_command_risk of the file src/tools/builtin/shell.rs… Patch available Fix from $1,6002026-08-06 MEDIUM 6.3 CVE-2026-18976 A vulnerability was determined in NousResearch hermes-agent up to 0.16.0. This impacts the function get_tool_definitions of the file agent/agent_init… Patch available Fix from $1,6002026-08-06 MEDIUM 5.3 CVE-2026-18974 A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the file server.py of the compon… No fix yet Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-18973 A vulnerability has been found in heshengtao super-agent-party up to 0.4.1. The impacted element is the function sanitize_proxy_url of the file serve… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-67873 A heap-based buffer overflow exists in lib60870-C 2.4.0 in the server-side FileSegment ASDU encoding path. The issue occurs because FileSegment_encod… No fix yet Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-67872 An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the event monitored-item queue resize handling No fix yet Fix from $1,9502026-08-06 HIGH 7.5 CVE-2026-67871 Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote attacker to cause a denial of service via the AddNodes, address_space_bs.c, sop… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.8 CVE-2026-67870 In open62541 v1.5.5, the server-side AddReferences implementation contains an incomplete validation flaw for non-local ExpandedNodeId targets. A remo… No fix yet Fix from $2,3002026-08-06 CRITICAL 9.8 CVE-2026-52466 Open Library Foundation VuFind v11.0.3 and v4.1 is vulnerable to toInorrect Access Control. The application fails to stop processing an incoming requ… No fix yet Fix from $2,3002026-08-06 HIGH 7.5 CVE-2026-67869 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Service_Call validates input argument… No fix yet Fix from $1,9502026-08-06 CRITICAL 9.3 CVE-2026-67531 FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 1.5.7, the sandboxed codecall:execute tool exposes live host … Patch available Fix from $2,3002026-08-06 MEDIUM 6.8 CVE-2026-19028 H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 computes the data length to checksum by subtracting the 4-byte trailing checksum size… Patch available Fix from $1,6002026-08-06 MEDIUM 6.9 CVE-2026-19027 The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, and H5Z__nbit_decompress_one_atomic functions in H5Znbit.c in HDF5 through 2.3.… Patch available Fix from $1,6002026-08-06 HIGH 7.3 CVE-2026-18970 A flaw has been found in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. The affected element is an unknown function of t… No fix yet Fix from $1,9502026-08-06 HIGH 7.3 CVE-2026-18969 A vulnerability was detected in Rongzhitong Visual Integrated Command and Dispatch Platform up to 20260617. Impacted is an unknown function of the fi… No fix yet Fix from $1,9502026-08-06