Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9733 CRITICAL 9.1 2026-06-23 Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, th…
CVE-2026-9732 MEDIUM 4.3 2026-06-03 The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This …
CVE-2026-9731 MEDIUM 4.3 2026-07-08 The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce val…
CVE-2026-9730 MEDIUM 4.3 2026-06-02 The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or inco…
CVE-2026-9729 MEDIUM 6.4 2026-07-23 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par…
CVE-2026-9728 MEDIUM 6.4 2026-08-24 The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live users…
CVE-2026-9726 CRITICAL Patched 9.8 2026-07-10 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This iss…
CVE-2026-9725 CRITICAL 9.1 2026-07-03 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is du…
CVE-2026-9724 MEDIUM 4.3 2026-06-24 The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida…
CVE-2026-9723 MEDIUM 4.3 2026-06-02 The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect…
CVE-2026-9722 MEDIUM 4.3 2026-06-02 The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce valid…
CVE-2026-9721 MEDIUM 4.3 2026-06-24 The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre…
CVE-2026-9720 MEDIUM 4.3 2026-07-29 The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing …
CVE-2026-9719 MEDIUM 4.3 2026-06-06 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5…
CVE-2026-9718 MEDIUM Patched 6.5 2026-06-25 CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s…
CVE-2026-9717 HIGH Patched 7.2 2026-06-25 CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with eleva…
CVE-2026-9716 HIGH Patched 7.5 2026-06-25 CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable…
CVE-2026-9714 MEDIUM 6.4 2026-05-29 The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and incl…
CVE-2026-9713 HIGH 7.5 2026-07-23 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed…
CVE-2026-9712 NONE — 2026-05-27 When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94…
CVE-2026-9711 CRITICAL 9.8 2026-06-30 The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and…
CVE-2026-9710 HIGH Patched 7.7 2026-06-24 The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to ever…
CVE-2026-9709 HIGH Patched 7.7 2026-06-24 The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of …
CVE-2026-9708 MEDIUM Patched 4.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel&hellip;
CVE-2026-9705 MEDIUM Patched 6.5 2026-06-25 A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerabil&hellip;