Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9145 | MEDIUM | 6.5 | 2026-07-02 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, an… | |
| CVE-2026-9143 | LOW | Patched | 3.7 | 2026-06-19 | There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a siz… |
| CVE-2026-9142 | CRITICAL | Patched | 9.1 | 2026-06-19 | There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback. This may allow an u… |
| CVE-2026-9140 | NONE | — | 2026-07-14 | A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to beco… | |
| CVE-2026-9138 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi… | |
| CVE-2026-9135 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies… |
| CVE-2026-9134 | MEDIUM | 6.4 | 2026-06-13 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31… | |
| CVE-2026-9132 | MEDIUM | Patched | 6.5 | 2026-06-30 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did n… |
| CVE-2026-9130 | HIGH | Patched | 7.1 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other u… |
| CVE-2026-9128 | HIGH | Patched | 7.5 | 2026-07-14 | A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified… |
| CVE-2026-9127 | HIGH | Patched | 7.5 | 2026-07-14 | A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated us… |
| CVE-2026-9125 | MEDIUM | 6.4 | 2026-06-12 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to,… | |
| CVE-2026-9109 | HIGH | 7.2 | 2026-06-13 | The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API… | |
| CVE-2026-9108 | HIGH | Patched | 7.5 | 2026-07-14 | A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize … |
| CVE-2026-9107 | MEDIUM | 6.4 | 2026-07-01 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter… | |
| CVE-2026-9106 | MEDIUM | Patched | 5.5 | 2026-06-30 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner mana… |
| CVE-2026-9105 | MEDIUM | Patched | 6.5 | 2026-06-29 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafte… |
| CVE-2026-9103 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The… |
| CVE-2026-9099 | HIGH | Patched | 7.7 | 2026-06-25 | A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited adm… |
| CVE-2026-9086 | HIGH | Patched | 7.3 | 2026-06-25 | A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoint… |
| CVE-2026-9085 | HIGH | Patched | 8.8 | 2026-07-05 | Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Cont… |
| CVE-2026-9083 | MEDIUM | Patched | 4.9 | 2026-06-25 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore par… |
| CVE-2026-9081 | HIGH | Patched | 7.1 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function fo… |
| CVE-2026-9080 | HIGH | Patched | 7.3 | 2026-07-03 | Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using … |
| CVE-2026-9079 | CRITICAL | Patched | 9.8 | 2026-07-03 | libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent tra… |