Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-68078 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Broker J 10.1.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-68073 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Broker J 10.1.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-67591 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Protonj2 1.2.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67590 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-67553 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-67552 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Proton Dotnet 1.1.0+ Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-67592 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Protonj2 1.2.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-67555 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-67554 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading… Qpid Proton Dotnet 1.1.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66276 An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to naive range handling, leading… Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-66275 An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service. This issue affects Apache … Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-66274 A pre-authentication attacker could leverage type nesting to cause a StackOverflowError potentially leading to denial of service. This issue affects… Qpid Proton J 0.35.0+ Fix from $1,9502026-08-05 MEDIUM 6.5 CVE-2026-66277 It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated attacker to cause excessive reso… Qpid Proton J 0.35.0+ Fix from $1,6002026-08-05 MEDIUM 6.5 CVE-2026-49004 The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabilities. This service listens … No fix yet Fix from $1,6002026-08-05 MEDIUM 5.3 CVE-2026-16981 The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capability, nonce, login, or owne… No fix yet Fix from $1,6002026-08-05 CRITICAL 10.0 CVE-2026-16940 The Custom Fields WordPress plugin before 1.5.1 does not validate a user-supplied file path before deletion, allowing unauthenticated users to delete… No fix yet Fix from $2,3002026-08-05 MEDIUM 6.5 CVE-2026-16968 The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users, allowing any authenticated … No fix yet Fix from $1,6002026-08-05 MEDIUM 5.4 CVE-2026-16942 The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page handlers, nor restrict it to user… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-16736 The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registrat… No fix yet Fix from $1,9502026-08-05 HIGH 7.2 CVE-2026-16605 The MultiVendorX WordPress plugin before 5.0.11 does not verify that the store targeted through its REST API belongs to the requesting vendor, allow… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16604 The Passster WordPress plugin before 4.3.6 outputs password-protected block content in the public page response before verifying the password, allow… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16603 The Passster WordPress plugin before 4.3.6 does not enforce its category-based content protection on the WordPress REST API, allowing unauthenticate… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16602 The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST endpoint,… No fix yet Fix from $1,9502026-08-05 MEDIUM 6.1 CVE-2026-16583 The Orbit Fox: Duplicate Page, Menu Icons, SVG Support, Cookie Notice, Custom Fonts & More WordPress plugin before 3.0.8 does not sanitize uploaded S… No fix yet Fix from $1,6002026-08-05 HIGH 7.5 CVE-2026-16573 The Bit Form WordPress plugin before 3.2.0 does not sanitize an uploaded signature image before storing it, allowing unauthenticated attackers to up… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16561 The Sunshine Photo Cart WordPress plugin before 3.6.12 does not perform access control checks in one of its AJAX actions, allowing unauthenticated u… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16055 The Contest Gallery WordPress plugin before 30.0.7 does not route its front-end login through the standard WordPress authentication flow, issuing an… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-16036 The miniOrange 2FA WordPress plugin before 6.2.7 does not bind the second factor being configured during the pre-login two-factor challenge to the t… No fix yet Fix from $1,9502026-08-05 HIGH 7.5 CVE-2026-15372 The WP 2FA WordPress plugin before 4.1.0 does not validate the second authentication factor when one of its supported methods is selected at login, … No fix yet Fix from $1,9502026-08-05 CRITICAL 9.1 CVE-2026-15360 The Ajax Load More WordPress plugin before 8.0.1 does not properly sanitise and escape a parameter before using it in a SQL query, allowing unauthen… Mitigation only Fix from $2,3002026-08-05