Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9237 | MEDIUM | 4.3 | 2026-07-09 | The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. Thi… | |
| CVE-2026-9236 | MEDIUM | 4.3 | 2026-05-27 | The CM Ad Changer – A simple tool to control and optimize your site's banners plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and in… | |
| CVE-2026-9235 | MEDIUM | 4.3 | 2026-07-09 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing n… | |
| CVE-2026-9234 | MEDIUM | 4.3 | 2026-06-02 | The JTL-Connector for WooCommerce plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.4.1. This is due to missing capability che… | |
| CVE-2026-9233 | MEDIUM | 4.3 | 2026-06-27 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This … | |
| CVE-2026-9230 | MEDIUM | 4.3 | 2026-07-03 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This … | |
| CVE-2026-9228 | MEDIUM | 4.3 | 2026-05-28 | The Timetable and Event Schedule by MotoPress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.4.16 via the ac… | |
| CVE-2026-9224 | MEDIUM | Patched | 4.3 | 2026-05-22 | Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a cr… |
| CVE-2026-9223 | MEDIUM | Patched | 4.3 | 2026-05-22 | Missing authorization in the vault import feature in Devolutions Server 2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a craft… |
| CVE-2026-9219 | MEDIUM | 6.5 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional … | |
| CVE-2026-9210 | MEDIUM | Patched | 4.5 | 2026-06-09 | Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modificatio… |
| CVE-2026-9204 | MEDIUM | Patched | 5.3 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions … |
| CVE-2026-9199 | MEDIUM | 4.3 | 2026-06-18 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… | |
| CVE-2026-9197 | MEDIUM | 4.9 | 2026-06-06 | The Smart Slider 3 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.5.1.36 via the replaceHTMLImage function. This makes it… | |
| CVE-2026-9189 | MEDIUM | 5.3 | 2026-05-29 | The Contact Form 7 – PayPal & Stripe Add-on plugin for WordPress is vulnerable to Payment Bypass via Insufficient Verification of Data Authenticity in all versions up to, a… | |
| CVE-2026-9188 | MEDIUM | 5.3 | 2026-07-02 | The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and includ… | |
| CVE-2026-9187 | MEDIUM | 5.3 | 2026-06-16 | The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capa… | |
| CVE-2026-9186 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h… | |
| CVE-2026-9184 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu… | |
| CVE-2026-9183 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block… | |
| CVE-2026-9180 | MEDIUM | 5.3 | 2026-07-03 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This i… | |
| CVE-2026-9175 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This… | |
| CVE-2026-9172 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability … | |
| CVE-2026-9162 | MEDIUM | Patched | 4.3 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connection… |
| CVE-2026-9156 | MEDIUM | Patched | 6.5 | 2026-05-27 | Tanium addressed a denial of service vulnerability in Tanium Server. |