Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 251–275 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9237 MEDIUM 4.3 2026-07-09 The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. Thi…
CVE-2026-9236 MEDIUM 4.3 2026-05-27 The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in…
CVE-2026-9235 MEDIUM 4.3 2026-07-09 The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing n…
CVE-2026-9234 MEDIUM 4.3 2026-06-02 The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability che…
CVE-2026-9233 MEDIUM 4.3 2026-06-27 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This …
CVE-2026-9230 MEDIUM 4.3 2026-07-03 The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This …
CVE-2026-9228 MEDIUM 4.3 2026-05-28 The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the ac…
CVE-2026-9224 MEDIUM Patched 4.3 2026-05-22 Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a cr…
CVE-2026-9223 MEDIUM Patched 4.3 2026-05-22 Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a craft…
CVE-2026-9219 MEDIUM 6.5 2026-06-26 Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional …
CVE-2026-9210 MEDIUM Patched 4.5 2026-06-09 Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modificatio…
CVE-2026-9204 MEDIUM Patched 5.3 2026-06-11 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions …
CVE-2026-9199 MEDIUM 4.3 2026-06-18 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and…
CVE-2026-9197 MEDIUM 4.9 2026-06-06 The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it…
CVE-2026-9189 MEDIUM 5.3 2026-05-29 The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, a…
CVE-2026-9188 MEDIUM 5.3 2026-07-02 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and includ…
CVE-2026-9187 MEDIUM 5.3 2026-06-16 The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capa…
CVE-2026-9186 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h…
CVE-2026-9184 MEDIUM 4.3 2026-06-24 The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu…
CVE-2026-9183 MEDIUM 4.3 2026-06-24 The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block…
CVE-2026-9180 MEDIUM 5.3 2026-07-03 The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This i…
CVE-2026-9175 MEDIUM 5.3 2026-06-24 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This…
CVE-2026-9172 MEDIUM 5.3 2026-06-24 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability …
CVE-2026-9162 MEDIUM Patched 4.3 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connection&hellip;
CVE-2026-9156 MEDIUM Patched 6.5 2026-05-27 Tanium addressed a denial of service vulnerability in Tanium Server.