Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.3 CVE-2026-65311 The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoint that changes the server's … No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-65310 ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration of affected versions, exposes its data and configuration endpoint without any a… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.4 CVE-2026-18218 A flaw was found in the TokenManager component of the Keycloak identity management service. When an administrator attempts to revoke tokens for a spe… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-65309 ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores and transmits user passwords using a reversible format instead of a one-way passw… No fix yet Fix from $1,9502026-07-31 MEDIUM 5.4 CVE-2026-18211 A flaw was found in the secure-client-uris client policy executor within Keycloak core services. This component is responsible for enforcing security… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 HIGH 8.1 CVE-2026-18215 Keycloak provides a way to let users log in using Microsoft accounts while restricting access to a specific organization (tenant). A flaw was discove… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-18214 Keycloak allows users to log in using Google accounts and can be configured to only allow users from specific Google Workspace domains. A flaw was fo… Build Of Keycloak No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-18208 A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source identity and access manageme… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-18203 A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a group policy is set to extend p… Build Of Keycloak No fix yet Fix from $1,6002026-07-31 MEDIUM 5.4 CVE-2026-8155 The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints, allowing any authenticated … No fix yet Fix from $1,6002026-07-31 CRITICAL 10.0 CVE-2026-18452 DMS+ (Non-Mobile) developed by Rich Source has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can exploit a fixed AP… No fix yet Fix from $2,3002026-07-31 HIGH 8.8 CVE-2026-16236 The Realtyna Organic IDX plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 5.3.0. This is due to missing … Mitigation only Fix from $1,9502026-07-31 HIGH 8.1 CVE-2026-15258 The Product Feed Manager For WooCommerce WordPress plugin before 7.6.1 does not properly sanitise and escape product-feed custom filter rules before… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-15209 The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a low-privileged authenticated… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-15048 The Geeky Bot WordPress plugin before 1.2.8 does not perform an authorization check on one of its AJAX actions, allowing unauthenticated users to re… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-14931 The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation and does not perform a capabi… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-14930 The JS Help Desk WordPress plugin before 3.1.4 does not perform any authorization, nonce, or ownership check on a front-end request dispatcher, allo… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-14928 The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning support-ticket content in a nonce… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.1 CVE-2026-14922 WP Photo Album Plus is vulnerable to stored Cross-Site Scripting in all versions up to, and including, 9.2.03.001 through a decode-after-sanitize (do… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.1 CVE-2026-14921 The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.5's shared link-rendering function, Ultimate_VC_Addons::uavc_link_init(), No fix yet Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-14919 The ShopMonitor.io WordPress plugin before 1.2.0 does not properly restrict its email-rerouting test mode, gating it behind a trusted-source check t… No fix yet Fix from $2,3002026-07-31 MEDIUM 6.1 CVE-2026-14845 The NewStatPress WordPress plugin before 1.4.5 does not sanitise and escape data derived from unauthenticated visitor requests before storing it and … No fix yet Fix from $1,6002026-07-31 MEDIUM 5.3 CVE-2026-14843 The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the targeted record when handling an un… No fix yet Fix from $1,6002026-07-31 MEDIUM 6.5 CVE-2026-14834 The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX action that adds subscribers … No fix yet Fix from $1,6002026-07-31 MEDIUM 6.8 CVE-2026-14833 The Lightbox with PhotoSwipe WordPress plugin before 5.9.0 does not sanitise or escape a link data attribute before rendering it into the image light… No fix yet Fix from $1,6002026-07-31 HIGH 7.5 CVE-2026-14830 The FlxWoo WordPress plugin before 3.1.1 does not verify with the payment processor that a checkout session was actually paid before marking the asso… No fix yet Fix from $1,9502026-07-31 MEDIUM 6.5 CVE-2026-14554 The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them in SQL queries, allowing use… No fix yet Fix from $1,6002026-07-31 CRITICAL 9.8 CVE-2026-14483 The Realtyna Organic IDX plugin + WPL Real Estate plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 5… Mitigation only Fix from $2,3002026-07-31 HIGH 7.5 CVE-2026-14333 The Demi WordPress plugin before 0.0.7 stores its full-site backup archives in a publicly accessible location under a predictable filename and witho… No fix yet Fix from $1,9502026-07-31 HIGH 7.5 CVE-2026-14319 The GiveWP WordPress plugin before 4.16.3 does not properly restrict access to a REST API endpoint that returns recurring-donation records, allowing… No fix yet Fix from $1,9502026-07-31