Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 276–300 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9019 | MEDIUM | 6.4 | 2026-06-10 | The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameter… | |
| CVE-2026-9017 | MEDIUM | 5.3 | 2026-07-11 | The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to t… | |
| CVE-2026-9013 | MEDIUM | 4.3 | 2026-06-19 | The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This ma… | |
| CVE-2026-9012 | NONE | — | 2026-08-21 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-9007 | NONE | — | 2026-07-15 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (… | |
| CVE-2026-9006 | HIGH | Patched | 7.4 | 2026-06-22 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unautho… |
| CVE-2026-9002 | MEDIUM | Patched | 6.5 | 2026-06-30 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The applica… |
| CVE-2026-8996 | MEDIUM | 6.5 | 2026-07-09 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the downloa… | |
| CVE-2026-8989 | MEDIUM | Patched | 6.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with phys… |
| CVE-2026-8988 | MEDIUM | Patched | 6.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. … |
| CVE-2026-8987 | HIGH | Patched | 8.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at… |
| CVE-2026-8986 | CRITICAL | Patched | 9.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv… |
| CVE-2026-8985 | CRITICAL | Patched | 9.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can su… |
| CVE-2026-8984 | CRITICAL | Patched | 9.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test … |
| CVE-2026-8983 | CRITICAL | Patched | 9.8 | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An atta… |
| CVE-2026-8982 | HIGH | Patched | 8.1 | 2026-07-21 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d… |
| CVE-2026-8944 | MEDIUM | 4.3 | 2026-06-30 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to mi… | |
| CVE-2026-8935 | CRITICAL | Patched | 9.8 | 2026-06-15 | The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing it… |
| CVE-2026-8934 | NONE | — | 2026-06-22 | A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to … | |
| CVE-2026-8933 | HIGH | 7.8 | 2026-07-21 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution en… | |
| CVE-2026-8932 | HIGH | Patched | 7.5 | 2026-07-03 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously … |
| CVE-2026-8927 | CRITICAL | Patched | 9.1 | 2026-07-03 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between req… |
| CVE-2026-8926 | CRITICAL | Patched | 9.1 | 2026-07-03 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, cur… |
| CVE-2026-8925 | CRITICAL | Patched | 9.8 | 2026-07-03 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same p… |
| CVE-2026-8924 | CRITICAL | Patched | 9.1 | 2026-07-03 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled or… |