Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9303 | MEDIUM | 4.3 | 2026-05-23 | A vulnerability was identified in calcom cal.diy up to 4.9.4. Impacted is an unknown function. The manipulation leads to cross-site request forgery. It is possible to initi… | |
| CVE-2026-9302 | MEDIUM | 6.3 | 2026-05-23 | A vulnerability was determined in 546669204 vps-inventory-monitoring up to 98c00b370668c96ae75e91c15548d9ea113652d9. This issue affects the function eval of the file app/in… | |
| CVE-2026-9301 | MEDIUM | 6.3 | 2026-05-23 | A vulnerability was found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGReset Message Handler. Performing a manipulation resul… | |
| CVE-2026-9300 | MEDIUM | 6.3 | 2026-05-23 | A vulnerability has been found in omec-project amf up to 2.1.1. This affects an unknown part of the component NGSetupRequest Handler. Such manipulation leads to memory corr… | |
| CVE-2026-9299 | MEDIUM | 6.3 | 2026-05-23 | A flaw has been found in omec-project amf up to 2.1.1. Affected by this issue is the function PDUSessionResourceModifyIndication of the file /go/src/amf/ngap/handler.go. Th… | |
| CVE-2026-9298 | MEDIUM | 6.3 | 2026-05-23 | A vulnerability was detected in omec-project amf up to 2.1.1. Affected by this vulnerability is an unknown functionality of the component PathSwitchRequest Handler. The man… | |
| CVE-2026-9297 | MEDIUM | 6.3 | 2026-05-23 | A security vulnerability has been detected in Edimax BR-6428NS 1.10. Affected is the function formWlbasic of the file /goform/formWlbasic of the component POST Request Hand… | |
| CVE-2026-9296 | MEDIUM | 6.3 | 2026-05-23 | A weakness has been identified in Edimax BR-6428NS 1.10. This impacts the function system of the file /goform/formWlanM of the component POST Request Handler. Executing a m… | |
| CVE-2026-9281 | MEDIUM | 6.4 | 2026-06-06 | The Master Addons For Elementor – Widgets, Extensions, Theme Builder, Popup Builder & Template Kits plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'j… | |
| CVE-2026-9280 | MEDIUM | 6.1 | 2026-06-06 | The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL Parameters in iframe Mode in all versions up to, and… | |
| CVE-2026-9278 | MEDIUM | Patched | 5.4 | 2026-06-15 | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script exec… |
| CVE-2026-9271 | MEDIUM | 5.9 | 2026-06-12 | Vulnerability Title | |
| CVE-2026-9263 | MEDIUM | Patched | 6.5 | 2026-06-30 | The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per t… |
| CVE-2026-9262 | MEDIUM | Patched | 6.5 | 2026-06-16 | Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9261 | MEDIUM | Patched | 6.8 | 2026-06-16 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9260 | MEDIUM | Patched | 6.2 | 2026-06-16 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9259 | MEDIUM | Patched | 6.5 | 2026-06-16 | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9258 | MEDIUM | Patched | 6.5 | 2026-06-16 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9251 | MEDIUM | Patched | 5.4 | 2026-05-22 | Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pendin… |
| CVE-2026-9246 | MEDIUM | Patched | 4.3 | 2026-05-22 | Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documen… |
| CVE-2026-9245 | MEDIUM | Patched | 5.0 | 2026-05-22 | Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-co… |
| CVE-2026-9243 | MEDIUM | 6.4 | 2026-05-29 | The Plus Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'carousel_direction' parameter of the Carousel Anything widget in ve… | |
| CVE-2026-9242 | MEDIUM | 5.3 | 2026-06-27 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient V… | |
| CVE-2026-9241 | MEDIUM | 4.3 | 2026-05-28 | The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to and in… | |
| CVE-2026-9240 | MEDIUM | 4.3 | 2026-07-09 | The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… |