Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-19723 | HIGH | Patched | 7.1 | 2026-09-02 | The Social Media Share Buttons & Social Sharing Icons WordPress plugin before 3.0.1 does not properly escape a value taken from the incoming request before outputting it in… |
| CVE-2026-19727 | MEDIUM | 6.1 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Syst… | |
| CVE-2026-19754 | NONE | — | 2026-09-02 | Baserow 2.3.3 contains a SQL injection vulnerability in the index() formula function. A low-privileged authenticated user who can create or modify formula fields can provid… | |
| CVE-2026-19766 | CRITICAL | Patched | 9.6 | 2026-09-01 | An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated a… |
| CVE-2026-19769 | HIGH | 7.2 | 2026-09-05 | The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Repeater Child 'type' Confusion via Unm… | |
| CVE-2026-19795 | MEDIUM | 6.2 | 2026-09-03 | Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segme… | |
| CVE-2026-19796 | HIGH | 7.2 | 2026-09-01 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter… | |
| CVE-2026-19806 | HIGH | 8.8 | 2026-09-01 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administ… | |
| CVE-2026-19820 | NONE | — | 2026-09-01 | A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a b… | |
| CVE-2026-19843 | HIGH | 8.4 | 2026-09-07 | A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor constructs an ldapsearch command by embedding an LDAP entry's distinguished name (DN) into a shell co… | |
| CVE-2026-19858 | HIGH | Patched | 7.5 | 2026-09-05 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not perform authorisation checks when resolving request-derived data during page rende… |
| CVE-2026-19859 | MEDIUM | Patched | 6.5 | 2026-09-06 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute a… |
| CVE-2026-19861 | MEDIUM | Patched | 4.7 | 2026-09-05 | The JetFormBuilder — Dynamic Blocks Form Builder WordPress plugin before 3.6.5.2 does not properly sanitise and escape a form field's value before including it in the HTML … |
| CVE-2026-19862 | MEDIUM | Patched | 4.8 | 2026-09-06 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to th… |
| CVE-2026-19887 | HIGH | 8.8 | 2026-09-05 | The Welcart e-Commerce plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.12.1 via deserialization of untrusted input in the… | |
| CVE-2026-19914 | HIGH | 7.2 | 2026-09-01 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due t… | |
| CVE-2026-19931 | NONE | — | 2026-09-06 | A flaw in libcurl makes it wrongly reuse an HTTP connection setup for a given hostname using Negotiate authentication, when the initial request is done using empty credenti… | |
| CVE-2026-19948 | MEDIUM | 5.3 | 2026-09-01 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versio… | |
| CVE-2026-19952 | HIGH | 7.5 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all … | |
| CVE-2026-20212 | CRITICAL | 9.8 | 2026-09-02 | A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privilege… | |
| CVE-2026-20274 | CRITICAL | 9.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20275 | HIGH | 8.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20276 | HIGH | 8.6 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20277 | HIGH | 8.2 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … | |
| CVE-2026-20278 | HIGH | 8.8 | 2026-09-02 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security … |