Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 301–325 of 78,575 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9626 | MEDIUM | 6.4 | 2026-07-03 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and incl… | |
| CVE-2026-9625 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to c… | |
| CVE-2026-9624 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length valida… | |
| CVE-2026-9622 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, r… | |
| CVE-2026-9621 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the … | |
| CVE-2026-9620 | MEDIUM | 6.4 | 2026-06-24 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0… | |
| CVE-2026-9619 | MEDIUM | 4.3 | 2026-06-24 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not pr… | |
| CVE-2026-9618 | MEDIUM | 4.3 | 2026-05-28 | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Fo… | |
| CVE-2026-9617 | MEDIUM | Patched | 6.8 | 2026-05-27 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If… |
| CVE-2026-9616 | MEDIUM | 4.3 | 2026-06-24 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve… | |
| CVE-2026-9614 | HIGH | 8.8 | 2026-06-01 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access. | |
| CVE-2026-9612 | MEDIUM | 5.3 | 2026-06-24 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y… | |
| CVE-2026-9611 | NONE | — | 2026-07-31 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be… | |
| CVE-2026-9610 | LOW | 2.3 | 2026-06-22 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by di… | |
| CVE-2026-9609 | MEDIUM | 4.7 | 2026-05-27 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The at… | |
| CVE-2026-9608 | LOW | 2.4 | 2026-05-27 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Exec… | |
| CVE-2026-9607 | MEDIUM | 6.3 | 2026-05-27 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation… | |
| CVE-2026-9606 | HIGH | 7.3 | 2026-05-27 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argumen… | |
| CVE-2026-9605 | HIGH | 7.3 | 2026-05-27 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation c… | |
| CVE-2026-9604 | MEDIUM | 4.3 | 2026-05-26 | A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/… | |
| CVE-2026-9603 | MEDIUM | 6.5 | 2026-05-26 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The man… | |
| CVE-2026-9602 | MEDIUM | Patched | 6.5 | 2026-07-17 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to … |
| CVE-2026-9599 | MEDIUM | 4.3 | 2026-06-02 | The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce vali… | |
| CVE-2026-9597 | MEDIUM | Patched | 5.4 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, w… |
| CVE-2026-9595 | MEDIUM | Patched | 5.3 | 2026-06-15 | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it … |