Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-23585 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23586 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23587 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23588 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23589 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23590 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-23591 | NONE | — | 2026-09-02 | Rejected reason: Withdrawn by requester. | |
| CVE-2026-2390 | MEDIUM | 6.4 | 2026-09-07 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This… | |
| CVE-2026-2520 | MEDIUM | 5.4 | 2026-09-08 | The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t… | |
| CVE-2026-25706 | HIGH | 7.5 | 2026-09-01 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - … | |
| CVE-2026-2573 | MEDIUM | 6.4 | 2026-09-03 | The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCs… | |
| CVE-2026-2688 | MEDIUM | Patched | 6.5 | 2026-09-02 | The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks… |
| CVE-2026-27086 | MEDIUM | Patched | 6.5 | 2026-09-04 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: fr… |
| CVE-2026-27347 | MEDIUM | 5.3 | 2026-09-04 | Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a t… | |
| CVE-2026-27432 | MEDIUM | Patched | 5.4 | 2026-09-04 | Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. Thi… |
| CVE-2026-2811 | MEDIUM | Patched | 5.4 | 2026-09-02 | The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. Th… |
| CVE-2026-31020 | CRITICAL | 9.8 | 2026-09-04 | In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionalit… | |
| CVE-2026-3174 | HIGH | 7.5 | 2026-09-08 | The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endp… | |
| CVE-2026-31911 | MEDIUM | 5.5 | 2026-09-05 | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminat… | |
| CVE-2026-31912 | MEDIUM | 5.5 | 2026-09-05 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset th… | |
| CVE-2026-32480 | MEDIUM | 5.3 | 2026-09-04 | Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membershi… | |
| CVE-2026-32773 | MEDIUM | Patched | 6.1 | 2026-09-02 | There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead… |
| CVE-2026-33197 | NONE | — | 2026-09-08 | AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vu… | |
| CVE-2026-33387 | MEDIUM | 4.6 | 2026-09-08 | A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required … | |
| CVE-2026-33388 | HIGH | 7.4 | 2026-09-08 | An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with … |