Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-49221 Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.4, Vvveb backend digital asset… Patch available Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-46482 ### Impact The registration component does not validate the text-based _Security Question_ CAPTCHA correctly, allowing attackers to bypass the challe… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-45734 MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce single-use semantics, allowing remot… Patch available Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-45125 MyBB is free and open source forum software. Prior to 1.8.40, the Email User controller does not sanitize sender names correctly, resulting in mail h… Patch available Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-45120 MyBB is free and open source forum software. Prior to 1.8.40, the calendar module does not verify private event status consistently, allowing users w… Patch available Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-45118 MyBB is free and open source forum software. Prior to 1.8.40, the Contact module does not validate a redirect URL or protocol correctly, resulting in… No fix yet Fix from $5,7502026-08-18 CRITICAL 9.8 CVE-2026-45117 MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape user-supplied database configura… Patch available Fix from $5,7502026-08-18 HIGH 8.7 CVE-2026-45116 MyBB is free and open source forum software. Prior to 1.8.40, the user datahandler does not properly validate checkbox and multiselect profile field … Patch available Fix from $4,9002026-08-18 HIGH 8.7 CVE-2026-45115 MyBB is free and open source forum software. Prior to 1.8.40, the Buddy/Ignore component does not sanitize usernames correctly, allowing attackers to… No fix yet Fix from $4,9002026-08-18 HIGH 8.8 CVE-2026-19501 CSV export functionality in Brainstorm Force SureForms version, <= 2.12.1, fails to neutralize spreadsheet formula characters in user-controlled form… Fix unknown Fix from $4,9002026-08-18 HIGH 7.5 CVE-2026-19500 The Entries component in Brainstorm Force SureForms version, less than 2.12.3, does not enforce adequate limits on user-controlled form fields or sub… No fix yet Fix from $4,9002026-08-18 MEDIUM 6.0 CVE-2026-15806 The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth, d… Patch available Fix from $4,0002026-08-18 CRITICAL 9.6 CVE-2026-12564 A flaw was found in the AAP Controller's HashiCorp Vault credential plugin. The kubernetes_auth() function in awx_plugins/credentials/hashivault.py r… No fix yet Fix from $5,7502026-08-18 HIGH 8.5 CVE-2026-75898 RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py). The … Patch available Fix from $4,9002026-08-18 MEDIUM 6.9 CVE-2026-75872 HTML Injection in the public subscription form in maalfer MailerUp before 1.1.3 allows unauthenticated remote attackers to have the application send … Patch available Fix from $4,0002026-08-18 CRITICAL 10.0 CVE-2026-75784 A vulnerability was detected in TRENDnet TEW-WLC100 1v2.07b01. Affected by this issue is the function FUN_0040da4c of the file /usr/nginx/sbin/nginx … No fix yet Fix from $5,7502026-08-18 MEDIUM 6.3 CVE-2026-75032 A flaw was found in BlueZ. Insufficient validation of packet length fields in GetFolderItems responses within the Audio/Video Remote Control Profile … No fix yet Fix from $4,0002026-08-18 CRITICAL 9.3 CVE-2026-74015 Unauthenticated SQL Injection in Readabler < 2.0.18 versions. No fix yet Fix from $5,7502026-08-18 HIGH 8.8 CVE-2026-74012 Deserialization of Untrusted Data vulnerability in TaxoPress allows Object Injection. This issue affects TaxoPress: from n/a through 3.51.0. No fix yet Fix from $4,9002026-08-18 MEDIUM 5.3 CVE-2026-74009 Unauthenticated Insecure Direct Object References (IDOR) in Razorpay for WooCommerce <= 4.8.7 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-74008 Unauthenticated Sensitive Data Exposure in Shortcodes and extra features for Phlox theme <= 2.17.22 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.3 CVE-2026-74007 Unauthenticated Sensitive Data Exposure in 3D FlipBook – PDF Flipbook Viewer, Flipbook Image Gallery <= 1.16.20 versions. No fix yet Fix from $4,0002026-08-18 MEDIUM 5.4 CVE-2026-74004 Subscriber Broken Access Control in Gravity Booster &#8211; Styles &amp; Layouts for Gravity Forms <= 6.0 versions. No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73997 Unauthenticated Denial of Service Attack in Starter Templates by Kadence WP <= 2.3.3 versions. No fix yet Fix from $4,9002026-08-18 CRITICAL 9.8 CVE-2026-73996 Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions. No fix yet Fix from $5,7502026-08-18 MEDIUM 5.4 CVE-2026-73995 Subscriber Broken Authentication in User Registration <= 5.2.6 versions. No fix yet Fix from $4,0002026-08-18 HIGH 7.5 CVE-2026-73994 Unauthenticated Broken Access Control in Charitable <= 1.8.11.3 versions. No fix yet Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73404 Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions. No fix yet Fix from $4,0002026-08-18 HIGH 8.1 CVE-2026-73400 Unauthenticated Local File Inclusion in Restaurant Menu by MotoPress <= 2.4.11 versions. No fix yet Fix from $4,9002026-08-18 MEDIUM 6.5 CVE-2026-73399 Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions. No fix yet Fix from $4,0002026-08-18