Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9153 MEDIUM 6.5 2026-06-25 Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to in…
CVE-2026-9150 MEDIUM Patched 6.5 2026-05-20 A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository m…
CVE-2026-9149 MEDIUM Patched 6.5 2026-05-21 A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the …
CVE-2026-9145 MEDIUM 6.5 2026-07-02 The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, an…
CVE-2026-9138 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi…
CVE-2026-9136 MEDIUM Patched 6.5 2026-05-20 A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the …
CVE-2026-9134 MEDIUM 6.4 2026-06-13 The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31…
CVE-2026-9132 MEDIUM Patched 6.5 2026-06-30 A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did n…
CVE-2026-9125 MEDIUM 6.4 2026-06-12 The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to,…
CVE-2026-9124 MEDIUM Patched 5.3 2026-05-20 Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak c…
CVE-2026-9122 MEDIUM Patched 6.5 2026-05-20 Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a cr…
CVE-2026-9116 MEDIUM Patched 4.3 2026-05-20 Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (C…
CVE-2026-9115 MEDIUM Patched 4.3 2026-05-20 Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page…
CVE-2026-9113 MEDIUM Patched 4.3 2026-05-20 Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromi…
CVE-2026-9110 MEDIUM Patched 4.2 2026-05-20 Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoo…
CVE-2026-9107 MEDIUM 6.4 2026-07-01 The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter…
CVE-2026-9106 MEDIUM Patched 5.5 2026-06-30 A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner mana…
CVE-2026-9105 MEDIUM Patched 6.5 2026-06-29 An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafte…
CVE-2026-9104 MEDIUM 6.4 2026-05-22 The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input …
CVE-2026-9101 MEDIUM 4.3 2026-05-20 Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading…
CVE-2026-9100 MEDIUM 5.9 2026-05-20 The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause a…
CVE-2026-9091 MEDIUM 5.3 2026-05-28 Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code pa…
CVE-2026-9087 MEDIUM 6.4 2026-05-20 A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually ver…
CVE-2026-9083 MEDIUM Patched 4.9 2026-06-25 A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore par…
CVE-2026-9078 MEDIUM Patched 5.4 2026-05-25 Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname co…