Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9073 MEDIUM 6.2 2026-06-23 A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism log…
CVE-2026-9066 MEDIUM Patched 6.1 2026-07-23 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java…
CVE-2026-9056 MEDIUM 5.4 2026-05-20 A stored cross-site scripting vulnerability has been found in the Talend Administration Center. An attacker with permission to manage servers can store a XSS payload that c…
CVE-2026-9050 MEDIUM 4.3 2026-06-02 The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not prope…
CVE-2026-9048 MEDIUM 4.3 2026-06-02 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it …
CVE-2026-9036 MEDIUM 5.9 2026-09-03 IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv…
CVE-2026-9035 MEDIUM Patched 6.5 2026-05-27 IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Tr…
CVE-2026-9028 MEDIUM 5.3 2026-07-09 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.7.4. This is due to the plugin …
CVE-2026-9027 MEDIUM 5.3 2026-07-09 The CorvusPay WooCommerce Payment Gateway plugin for WordPress is vulnerable to Payment Bypass via Improper Verification of Cryptographic Signature in all versions up to, a…
CVE-2026-9022 MEDIUM 6.4 2026-05-27 The Splide Carousel Block plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'url' Block Attribute in all versions up to, and including, 1.7.1 due to ins…
CVE-2026-9021 MEDIUM 5.3 2026-07-09 The Easy Invoice plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.19. This is due to the plugin registering the easy_invoic…
CVE-2026-9019 MEDIUM 6.4 2026-06-10 The Easy Image Collage plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'grid[properties][borderColor]' and 'grid[images][N][attachment_url]' Parameter…
CVE-2026-9017 MEDIUM 5.3 2026-07-11 The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to t…
CVE-2026-9016 MEDIUM 5.3 2026-06-06 The Debug Log Manager – Conveniently Monitor and Inspect Errors plugin for WordPress is vulnerable to Improper Output Neutralization for Logs in all versions up to, and inc…
CVE-2026-9015 MEDIUM 4.3 2026-05-28 The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and…
CVE-2026-9014 MEDIUM 5.3 2026-05-27 The WP Promoter plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the reset_stats() function in versions up to, a…
CVE-2026-9013 MEDIUM 4.3 2026-06-19 The Bogo plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.9.1 via the bogo_rest_create_post_translation. This ma…
CVE-2026-9008 MEDIUM 4.3 2026-06-06 The Page-list plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 6.2. This is due to the pagelist_unqprfx_ext_shortcode() fun…
CVE-2026-9002 MEDIUM Patched 6.5 2026-06-30 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The applica…
CVE-2026-8996 MEDIUM 6.5 2026-07-09 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the downloa…
CVE-2026-8995 MEDIUM 4.3 2026-05-29 The Poll Maker – Versus Polls, Anonymous Polls, Image Polls plugin for WordPress is vulnerable to Sensitive Information Exposure in versions up to and including 6.3.7. This…
CVE-2026-8993 MEDIUM 6.5 2026-06-02 D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could …
CVE-2026-8991 MEDIUM 4.4 2026-06-06 The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'drag_n_drop_text' and 'drag_n_drop_browse_t…
CVE-2026-8989 MEDIUM Patched 6.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with phys…
CVE-2026-8988 MEDIUM Patched 6.8 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. …