Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9145 MEDIUM 6.5 2026-07-02 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, an…
CVE-2026-9143 LOW Patched 3.7 2026-06-19 There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen.  This may silently discard high bits if a siz…
CVE-2026-9142 CRITICAL Patched 9.1 2026-06-19 There is an insecure default credentials vulnerability in NI grpc-device when TLS configuration is not present and the server is bound beyond loopback.  This may allow an u…
CVE-2026-9140 NONE — 2026-07-14 A denial-of-service security issue exists in the 1719-AENTR. The security issue stems from improper handling of a UDP unicast network storm, which causes the device to beco…
CVE-2026-9138 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi…
CVE-2026-9135 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies…
CVE-2026-9134 MEDIUM 6.4 2026-06-13 The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31…
CVE-2026-9132 MEDIUM Patched 6.5 2026-06-30 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did n…
CVE-2026-9130 HIGH Patched 7.1 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other u…
CVE-2026-9128 HIGH Patched 7.5 2026-07-14 A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified…
CVE-2026-9127 HIGH Patched 7.5 2026-07-14 A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated us…
CVE-2026-9125 MEDIUM 6.4 2026-06-12 The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to,…
CVE-2026-9109 HIGH 7.2 2026-06-13 The GPTranslate – Multilingual AI Translation for WordPress: Automatically Translate Websites plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API…
CVE-2026-9108 HIGH Patched 7.5 2026-07-14 A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize …
CVE-2026-9107 MEDIUM 6.4 2026-07-01 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter…
CVE-2026-9106 MEDIUM Patched 5.5 2026-06-30 A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner mana…
CVE-2026-9105 MEDIUM Patched 6.5 2026-06-29 An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafte…
CVE-2026-9103 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The…
CVE-2026-9099 HIGH Patched 7.7 2026-06-25 A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited adm…
CVE-2026-9086 HIGH Patched 7.3 2026-06-25 A flaw was found in Keycloak. A remote attacker with administrative privileges, specifically those with `manage-client` permission or access to client registration endpoint…
CVE-2026-9085 HIGH Patched 8.8 2026-07-05 Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Cont…
CVE-2026-9083 MEDIUM Patched 4.9 2026-06-25 A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore par…
CVE-2026-9081 HIGH Patched 7.1 2026-08-05 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function fo…
CVE-2026-9080 HIGH Patched 7.3 2026-07-03 Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using …
CVE-2026-9079 CRITICAL Patched 9.8 2026-07-03 libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent tra…