Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-28147 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorr… No fix yet Fix from $1,6002026-08-03 HIGH 7.5 CVE-2026-21555 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21554 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21553 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21552 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21551 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21550 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21549 In modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed No fix yet Fix from $1,9502026-08-03 HIGH 7.5 CVE-2026-21548 In nr modem, there is a possible improper input validation. This could lead to remote denial of service with System execution privileges needed. No fix yet Fix from $1,9502026-08-03 MEDIUM 5.6 CVE-2026-18593 A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmp… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.3 CVE-2026-18590 A vulnerability was determined in Wavlink WL-NU516U1 708c073-mt7628. Affected is the function set_sys_adm of the file adm.cgi of the component Admin … No fix yet Fix from $1,6002026-08-03 MEDIUM 5.3 CVE-2026-12259 In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to disk and may extract them bef… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.7 CVE-2026-9593 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a … No fix yet Fix from $1,6002026-08-03 HIGH 7.3 CVE-2026-4793 An incorrect default permissions vulnerability in Synology Assistant before 7.0.7-50095 allows local users to read or write arbitrary files and condu… Assistant 7.0.7-50095+ Fix from $1,9502026-08-03 CRITICAL 9.8 CVE-2026-18589 A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This impacts the function change_password of the file nas.cgi. The manipulation of th… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-18588 A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. This affects the function fgets of the file nas.cgi. The manipulation of the arg… No fix yet Fix from $2,3002026-08-03 HIGH 7.5 CVE-2026-18587 A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impacted element is an unknown function of the component Config Import. Executing a m… No fix yet Fix from $1,9502026-08-03 HIGH 8.6 CVE-2026-16572 The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a SQL query, allowing unauthen… No fix yet Fix from $1,9502026-08-03 MEDIUM 6.5 CVE-2026-16563 The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when returning a single lesson through i… No fix yet Fix from $1,6002026-08-03 HIGH 8.1 CVE-2026-16539 The sm page duplicator WordPress plugin through 1.0.0 does not sanitise and escape a stored value before using it in a SQL statement when duplicating… No fix yet Fix from $1,9502026-08-03 CRITICAL 9.1 CVE-2026-16534 The Import and export users and customers WordPress plugin before 2.4.2 does not enforce WordPress's role-assignment and per-user edit permissions du… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.1 CVE-2026-16532 The Link Library WordPress plugin before 7.9.3 does not properly sanitise and escape a user-supplied value before using it in a SQL query, allowing u… Mitigation only Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16300 The ChamaWP WordPress plugin before 1.0.13 does not properly validate a password reset request, allowing unauthenticated attackers to reset the pass… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16250 The Personal QR Message WordPress plugin through 1.0 does not restrict the file types that can be uploaded through an unauthenticated handler, allowi… No fix yet Fix from $2,3002026-08-03 CRITICAL 9.8 CVE-2026-16060 The Insert or Embed Articulate Content into WordPress plugin through 4.3000000027 does not correctly validate the contents of an uploaded archive, re… No fix yet Fix from $2,3002026-08-03 MEDIUM 6.5 CVE-2026-16057 The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its post-deletion handlers, gati… No fix yet Fix from $1,6002026-08-03 MEDIUM 6.1 CVE-2026-15931 The Simple Membership WordPress plugin before 4.7.8 does not sanitise a subscriber name value received from an unauthenticated payment approval reque… No fix yet Fix from $1,6002026-08-03 CRITICAL 9.4 CVE-2026-15930 The Simple Membership WordPress plugin before 4.7.8 does not verify whether user creation failed during registration before using the returned value … No fix yet Fix from $2,3002026-08-03 MEDIUM 6.1 CVE-2026-15383 The Blog Floating Button WordPress plugin through 1.4.20 does not sanitize or escape the visitor User-Agent header, which it stores through an unauth… No fix yet Fix from $1,6002026-08-03 CRITICAL 9.8 CVE-2026-12872 The Webinfos WordPress plugin through 1.2 does not validate the type or name of uploaded files, nor restrict the upload action with any authenticatio… No fix yet Fix from $2,3002026-08-03