Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,493 CVEs

EOL hidden · Show all products

CVEs (78,493, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 301–325 of 78,493 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-80133 HIGH 7.4 2026-09-07 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Relative Path Traversal vulnerability. An unauthen…
CVE-2026-80132 HIGH 8.1 2026-09-07 ell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authentication for Critical Function vulner…
CVE-2026-79678 HIGH 8.1 2026-09-07 A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDA…
CVE-2026-76578 CRITICAL 9.8 2026-09-07 A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. A…
CVE-2026-6431 HIGH 7.2 2026-09-07 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Bi…
CVE-2026-6223 CRITICAL 9.4 2026-09-07 Improper restriction of excessive authentication attempts vulnerability in Bahçelievler Muncipality BiHayat App allows Authentication Bypass. This issue affects BiHayat Ap…
CVE-2026-61410 CRITICAL 9.4 2026-09-07 Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains a Missing Authorization vulnerability. An unauthenti…
CVE-2026-61409 HIGH 7.3 2026-09-07 Dell Secure Connect Gateway (SCG) 5.0 Application, versions prior to 5.36.00.00, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command …
CVE-2026-4945 MEDIUM 5.3 2026-09-07 The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a…
CVE-2026-12853 MEDIUM 5.4 2026-09-07 The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a…
CVE-2022-51018 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create…
CVE-2022-51017 HIGH Patched 7.5 2026-09-07 PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_S…
CVE-2022-51016 MEDIUM Patched 6.1 2026-09-07 PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key c…
CVE-2022-51015 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In…
CVE-2022-51014 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s…
CVE-2022-51013 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran…
CVE-2022-51012 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte…
CVE-2022-51011 MEDIUM Patched 4.3 2026-09-07 PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large …
CVE-2022-51010 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra…
CVE-2026-86404 HIGH 8.8 2026-09-07 EAP's Artemis deserialization configuration permits deserialization by default. ObjectMessage.getObject() uses ObjectInputStreamWithClassLoader, which implements allow-list…
CVE-2026-86301 LOW 3.5 2026-09-07 A vulnerability has been found in code-projects Hospital Information System 1.0. Affected is an unknown function of the file /HIS/src/patients/editPatient.php of the compon…
CVE-2026-86300 HIGH 7.3 2026-09-07 A flaw has been found in Tenda AC9 15.03.05.14. This impacts the function R7WebsSecurityHandler of the component Web Management. This manipulation causes improper authentic…
CVE-2026-86299 CRITICAL 9.9 2026-09-07 A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Ha…
CVE-2026-78325 NONE — 2026-09-07 Cross-site scripting in the Evernote and Google Keep note importers in Standard Notes for Android through 3.201.24 allows an attacker to execute arbitrary JavaScript in the…
CVE-2026-2390 MEDIUM 6.4 2026-09-07 The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This…