Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

CRITICAL 9.9 CVE-2026-63233 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment overall an… Mitigation only Fix from $2,3002026-07-29 CRITICAL 9.9 CVE-2026-63232 A SQL injection and unsafe deserialisation vulnerability in Koollab LMS allowed an authenticated attacker to inject through the assessment reinforcem… No fix yet Fix from $2,3002026-07-29 HIGH 8.1 CVE-2026-63231 A post-authentication SQL injection vulnerability in Koollab LMS allowed an authenticated attacker to use an error-based SQL oracle via the face-to-f… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.1 CVE-2026-63230 A pre-authentication error-based SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to read sensitive database contents, … No fix yet Fix from $2,3002026-07-29 CRITICAL 9.1 CVE-2026-63229 A pre-authentication blind SQL injection vulnerability in Koollab LMS allowed an unauthenticated attacker to use a time-based SQL oracle via the SSO … Mitigation only Fix from $2,3002026-07-29 HIGH 8.1 CVE-2026-14300 The miniOrange Social Login and Register (Discord, Google, Twitter, LinkedIn) WordPress plugin before 7.8.0 does not bind the one-time code used by i… No fix yet Fix from $1,9502026-07-29 HIGH 7.1 CVE-2026-14234 The WOLF WordPress plugin before 1.1.0 does not perform a nonce or capability check on one of its AJAX actions, allowing an unauthenticated attacker… No fix yet Fix from $1,9502026-07-29 CRITICAL 9.9 CVE-2026-63227 An unrestricted SCORM file upload vulnerability in Koollab LMS allowed an authenticated module designer to upload a SCORM package containing a PHP we… No fix yet Fix from $2,3002026-07-29 MEDIUM 5.4 CVE-2026-14224 The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data update action belongs to the… No fix yet Fix from $1,6002026-07-29 MEDIUM 5.3 CVE-2026-13692 The PayU CommercePro Plugin WordPress plugin before 3.9.0 does not verify the payment-gateway signature before applying order modifications, allowing… No fix yet Fix from $1,6002026-07-29 HIGH 7.4 CVE-2026-13690 The UsersWP WordPress plugin before 1.2.67 does not validate the selected authentication provider in its two-factor login handler, allowing an attac… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.8 CVE-2026-13605 The PhotoSwipe WordPress plugin through 4.1.1.1 uses the title attribute of author-supplied link markup as a lightbox caption that is written into th… No fix yet Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-13423 The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthenticated AJAX routes, which … No fix yet Fix from $2,3002026-07-29 HIGH 8.6 CVE-2026-11974 The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a file read operation in two A… No fix yet Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-11351 The ShinyStat Analytics WordPress plugin before 1.0.17 does not perform any authorization check on one of its REST API endpoints, allowing unauthenti… No fix yet Fix from $1,6002026-07-29 CRITICAL 9.8 CVE-2026-18072 The Advanced Responsive Video Embedder for Rumble, Odysee, YouTube, Vimeo, Kick … plugin for WordPress is vulnerable to Authentication Bypass via a H… No fix yet Fix from $2,3002026-07-29 HIGH 7.2 CVE-2026-12476 The Easy Digital Downloads plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to and including 3.6.9. This is due to insuffic… No fix yet Fix from $1,9502026-07-29 MEDIUM 6.4 CVE-2026-17162 The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'currentPostId' B… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.4 CVE-2026-17161 The WowStore – Store Builder & Product Blocks for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'filterMobileText… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.4 CVE-2026-15735 The Contact Form to Any API plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'cf7anyapi_form_field' Post Meta in all versions up… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.4 CVE-2026-12939 The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link' attribute of the post_thumbnail (and newsletter… No fix yet Fix from $1,6002026-07-29 MEDIUM 6.4 CVE-2026-12938 The Newsletters Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'target' attribute of the [newsletters_post] shortcode… No fix yet Fix from $1,6002026-07-29 HIGH 8.8 CVE-2026-12144 The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to … No fix yet Fix from $1,9502026-07-29 HIGH 7.4 CVE-2026-56822 Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateVali… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-29 HIGH 7.4 CVE-2026-56821 Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, the OcspServerCertificateVali… Netty 4.1.136 / 4.2.16+ Fix from $1,9502026-07-29 MEDIUM 5.3 CVE-2026-66064 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/handler.go sendFile handler opened f… Patch available Fix from $1,6002026-07-28 MEDIUM 6.5 CVE-2026-66063 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.5, the httpserver/updown.go multipart upload handler s… Patch available Fix from $1,6002026-07-28 CRITICAL 9.1 CVE-2026-64863 goshs is a feature-rich single-binary file server for red teamers and developers. Prior to 2.1.4, the httpserver/server.go wdGuard handled WebDAV MOV… Patch available Fix from $2,3002026-07-28 CRITICAL 9.1 CVE-2026-62325 goshs is a feature-rich single-binary file server for red teamers and developers. From 2.1.3 until 2.1.4, the sftpserver/sftpserver.go password handl… Patch available Fix from $2,3002026-07-28 MEDIUM 6.5 CVE-2026-59921 Netty is an asynchronous, event-driven network application framework. Prior to versions 4.1.136.Final and 4.2.16.Final, HttpPostRequestEncoder constr… Netty 4.1.136 / 4.2.16+ Fix from $1,6002026-07-28