Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 276–300 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9019 MEDIUM 6.4 2026-06-10 The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameter…
CVE-2026-9017 MEDIUM 5.3 2026-07-11 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to t…
CVE-2026-9013 MEDIUM 4.3 2026-06-19 The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This ma…
CVE-2026-9012 NONE — 2026-08-21 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-9007 NONE — 2026-07-15 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (…
CVE-2026-9006 HIGH Patched 7.4 2026-06-22 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unautho…
CVE-2026-9002 MEDIUM Patched 6.5 2026-06-30 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The applica…
CVE-2026-8996 MEDIUM 6.5 2026-07-09 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the downloa…
CVE-2026-8989 MEDIUM Patched 6.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with phys…
CVE-2026-8988 MEDIUM Patched 6.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. …
CVE-2026-8987 HIGH Patched 8.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at…
CVE-2026-8986 CRITICAL Patched 9.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv…
CVE-2026-8985 CRITICAL Patched 9.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can su…
CVE-2026-8984 CRITICAL Patched 9.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test …
CVE-2026-8983 CRITICAL Patched 9.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An atta…
CVE-2026-8982 HIGH Patched 8.1 2026-07-21 Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d…
CVE-2026-8944 MEDIUM 4.3 2026-06-30 The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to mi…
CVE-2026-8935 CRITICAL Patched 9.8 2026-06-15 The WP MAPS PRO WordPress plugin before 6.1.1 registers an unauthenticated AJAX action which, given a valid nonce that is publicly emitted on any frontend page enqueuing it…
CVE-2026-8934 NONE — 2026-06-22 A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to …
CVE-2026-8933 HIGH 7.8 2026-07-21 A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution en…
CVE-2026-8932 HIGH Patched 7.5 2026-07-03 libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously …
CVE-2026-8927 CRITICAL Patched 9.1 2026-07-03 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between req…
CVE-2026-8926 CRITICAL Patched 9.1 2026-07-03 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, cur…
CVE-2026-8925 CRITICAL Patched 9.8 2026-07-03 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same p…
CVE-2026-8924 CRITICAL Patched 9.1 2026-07-03 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled or…