Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9153 | MEDIUM | 6.5 | 2026-06-25 | Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to in… | |
| CVE-2026-9150 | MEDIUM | Patched | 6.5 | 2026-05-20 | A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository m… |
| CVE-2026-9149 | MEDIUM | Patched | 6.5 | 2026-05-21 | A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the … |
| CVE-2026-9145 | MEDIUM | 6.5 | 2026-07-02 | The Database for Contact Form 7, WPforms, Elementor forms plugin for WordPress is vulnerable to Arbitrary File Copy via the create_entry_el() function in versions up to, an… | |
| CVE-2026-9138 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi… | |
| CVE-2026-9136 | MEDIUM | Patched | 6.5 | 2026-05-20 | A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the … |
| CVE-2026-9134 | MEDIUM | 6.4 | 2026-06-13 | The FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attribute_key' shortcode parameter in versions up to, and including, 3.1.31… | |
| CVE-2026-9132 | MEDIUM | Patched | 6.5 | 2026-06-30 | A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from private repositories they did n… |
| CVE-2026-9125 | MEDIUM | 6.4 | 2026-06-12 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to,… | |
| CVE-2026-9124 | MEDIUM | Patched | 5.3 | 2026-05-20 | Insufficient validation of untrusted input in Input in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to leak c… |
| CVE-2026-9122 | MEDIUM | Patched | 6.5 | 2026-05-20 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to obtain potentially sensitive information from process memory via a cr… |
| CVE-2026-9116 | MEDIUM | Patched | 4.3 | 2026-05-20 | Insufficient policy enforcement in ServiceWorker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (C… |
| CVE-2026-9115 | MEDIUM | Patched | 4.3 | 2026-05-20 | Insufficient policy enforcement in Service Worker in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to bypass same origin policy via a crafted HTML page… |
| CVE-2026-9113 | MEDIUM | Patched | 4.3 | 2026-05-20 | Out of bounds read in GPU in Google Chrome on Mac prior to 148.0.7778.179 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromi… |
| CVE-2026-9110 | MEDIUM | Patched | 4.2 | 2026-05-20 | Inappropriate implementation in UI in Google Chrome on Windows prior to 148.0.7778.179 allowed a remote attacker who had compromised the renderer process to perform UI spoo… |
| CVE-2026-9107 | MEDIUM | 6.4 | 2026-07-01 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'meta[kaliforms_field_components]' parameter… | |
| CVE-2026-9106 | MEDIUM | Patched | 5.5 | 2026-06-30 | A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an organization's runner mana… |
| CVE-2026-9105 | MEDIUM | Patched | 6.5 | 2026-06-29 | An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafte… |
| CVE-2026-9104 | MEDIUM | 6.4 | 2026-05-22 | The Draft List plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Draft Post Title in all versions up to, and including, 2.6.3 due to insufficient input … | |
| CVE-2026-9101 | MEDIUM | 4.3 | 2026-05-20 | Prototype pollution in csv parsing logic during import can lead to untrusted file paths (but not arguments) entering shell.openExternal after specific user behavior leading… | |
| CVE-2026-9100 | MEDIUM | 5.9 | 2026-05-20 | The MongoDB C Driver's legacy GridFS API accepts malformed file metadata from the database without adequate validation. Crafted documents in a GridFS collection may cause a… | |
| CVE-2026-9091 | MEDIUM | 5.3 | 2026-05-28 | Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code pa… | |
| CVE-2026-9087 | MEDIUM | 6.4 | 2026-05-20 | A flaw was found in Keycloak. The cross-session verification proof is keyed only by (local userId, idpAlias) and is not bound to the upstream identity that was actually ver… | |
| CVE-2026-9083 | MEDIUM | Patched | 4.9 | 2026-06-25 | A flaw was found in Keycloak. A realm administrator with the "manage-realm" role can exploit this vulnerability by submitting an arbitrary filesystem path as a keystore par… |
| CVE-2026-9078 | MEDIUM | Patched | 5.4 | 2026-05-25 | Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname co… |