Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.8
CVE-2026-78211

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remote attackers can inject malic…

No fix yet
Fix from $5,750 2026-08-24
Unclassified CRITICAL 9.9
CVE-2026-78169

A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. This impacts the function strcpy of the file /goform/aspRemoteApConfTempS…

No fix yet
Fix from $5,750 2026-08-24
Unclassified CRITICAL 9.8
CVE-2026-78168

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_session_url of the component …

No fix yet
Fix from $5,750 2026-08-24
Unclassified CRITICAL 10.0
CVE-2026-78167

A weakness has been identified in EFM ipTIME T16000M 14.20.2. The impacted element is the function httpcon_check_session_url of the component Session…

No fix yet
Fix from $5,750 2026-08-24
Unclassified CRITICAL 9.4
CVE-2026-78207

exceljs-hardened before 5.0.0 contains a prototype pollution vulnerability in the deepMerge helper that fails to reject __proto__, constructor, or pr…

No fix yet
Fix from $5,750 2026-08-24
Unclassified CRITICAL 9.8
CVE-2026-8445

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in text nodes when converting a…

No fix yet
Fix from $5,750 2026-08-23
Unclassified CRITICAL 9.8
CVE-2026-7808

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g., script or style) to survive s…

No fix yet
Fix from $5,750 2026-08-23
Unclassified CRITICAL 9.8
CVE-2026-5388

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_string), HTML serialization, Ma…

No fix yet
Fix from $5,750 2026-08-23
Unclassified CRITICAL 9.9
CVE-2026-78155

privilege escalation in StackGres operator allows a low-privilege tenant who owns a database to gain administrator privileges

No fix yet
Fix from $5,750 2026-08-23
Unclassified CRITICAL 9.9
CVE-2026-78050

A vulnerability was found in Comfast CF-N1-S 2.6.0.1. The affected element is the function sub_41AD7C of the file /cgi-bin/mbox-config?method=SET&sec…

No fix yet
Fix from $5,750 2026-08-23
Unclassified CRITICAL 9.8
CVE-2026-4703

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.5
CVE-2026-77992

Joomla Extension - fabrikar.com - heredoc terminator breakout in the calc element in Fabrik < 4.7.2 - The onUpdateComment endpoint did not perform an…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 10.0
CVE-2026-76607

Joomla Extension - fabrikar.com - Missing ACL check in download element in Fabrik < 4.7.2.

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 10.0
CVE-2026-76606

Joomla Extension - fabrikar.com - Path Traversal via image element in Fabrik < 4.7.2.

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 10.0
CVE-2026-76605

Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 10.0
CVE-2026-76604

Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is vulnerable t…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.3
CVE-2026-76602

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in ORDER BY in Fabrik < 4.7.2 - The order parameter in list models is used in queries…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.3
CVE-2026-76571

Joomla Extension - fabrikar.com - Unauthenticated SQL injection in list filter condition parameter in Fabrik < 4.7.2 - The condition parameter passed…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 10.0
CVE-2026-77946

A vulnerability was determined in TRENDnet TEW-821DAP 2.2.01b05. Affected by this vulnerability is the function uci_safe_get of the file /cgi-bin/app…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-78003

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in versions up to and including…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.3
CVE-2026-12710

A Missing Authorization vulnerability in the QueryEngineTask of Google Cloud Application Integration (versions from 2025-04-28 to 2026-04-04) allows …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity it is asked to authenticate, …

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authentication, authorisation or no…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.8
CVE-2026-77000

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with the identity provider before…

No fix yet
Fix from $5,750 2026-08-22
Unclassified CRITICAL 9.1
CVE-2026-49849

xShop is an open-source shop developed in Laravel. An Unrestricted File Upload vulnerability in xShop version 3.0.3 allows an authenticated administr…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77415

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, crafted JSONata expressions could chain several object-integrity weakn…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77414

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.1, the src/jsonata.js environment.lookup function used a bypassable hasOw…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.3
CVE-2026-77413

JSONata is a JSON query and transformation language. Prior to 1.8.8 and 2.2.0, the src/functions.js lookup function lacked an Object.prototype.hasOwn…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.8
CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to versions 33.6, 34.5, and 33.6,…

Patch available
Fix from $5,750 2026-08-21
Unclassified CRITICAL 9.9
CVE-2026-62283

Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. Nezha versions 1.14.13 through 1.14.14 and 2.0.0 thro…

Patch available
Fix from $5,750 2026-08-21