Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 251–275 of 78,575 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9704 | MEDIUM | 6.8 | 2026-05-27 | A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the Tok… | |
| CVE-2026-9702 | HIGH | Patched | 7.5 | 2026-06-25 | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destin… |
| CVE-2026-9701 | CRITICAL | 9.8 | 2026-07-08 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of th… | |
| CVE-2026-9700 | HIGH | 7.5 | 2026-07-08 | The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping… | |
| CVE-2026-9699 | MEDIUM | 6.8 | 2026-06-26 | Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server l… | |
| CVE-2026-9698 | CRITICAL | Patched | 9.8 | 2026-06-09 | DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were writt… |
| CVE-2026-9697 | HIGH | Patched | 7.4 | 2026-06-17 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SO… |
| CVE-2026-9695 | CRITICAL | 9.8 | 2026-07-08 | An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server. | |
| CVE-2026-9694 | LOW | Patched | 2.6 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, … |
| CVE-2026-9693 | LOW | Patched | 3.5 | 2026-08-17 | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a … |
| CVE-2026-9692 | MEDIUM | 5.3 | 2026-06-18 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built… | |
| CVE-2026-9691 | CRITICAL | 9.8 | 2026-06-15 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | |
| CVE-2026-9690 | HIGH | 7.5 | 2026-06-17 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. | |
| CVE-2026-9689 | MEDIUM | 4.2 | 2026-05-27 | A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Iden… | |
| CVE-2026-9680 | MEDIUM | 5.8 | 2026-07-28 | Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listeni… | |
| CVE-2026-9679 | MEDIUM | Patched | 5.9 | 2026-06-17 | Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal b… |
| CVE-2026-9678 | MEDIUM | Patched | 5.9 | 2026-06-17 | Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-… |
| CVE-2026-9677 | MEDIUM | 4.8 | 2026-06-27 | The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via … | |
| CVE-2026-9676 | MEDIUM | Patched | 4.3 | 2026-06-29 | The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with S… |
| CVE-2026-9675 | HIGH | Patched | 7.5 | 2026-06-17 | Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket se… |
| CVE-2026-9674 | MEDIUM | Patched | 4.3 | 2026-05-27 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds. |
| CVE-2026-9673 | MEDIUM | Patched | 6.8 | 2026-05-28 | Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can i… |
| CVE-2026-9669 | NONE | — | 2026-06-08 | bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted inpu… | |
| CVE-2026-9668 | MEDIUM | 6.3 | 2026-08-26 | With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. T… | |
| CVE-2026-9662 | HIGH | 8.1 | 2026-06-09 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validatio… |