Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-23585 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23586 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23587 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23588 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23589 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23590 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-23591 NONE — 2026-09-02 Rejected reason: Withdrawn by requester.
CVE-2026-2390 MEDIUM 6.4 2026-09-07 The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This…
CVE-2026-2520 MEDIUM 5.4 2026-09-08 The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on t…
CVE-2026-25706 HIGH 7.5 2026-09-01 Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - …
CVE-2026-2573 MEDIUM 6.4 2026-09-03 The GutenKit – Page Builder Blocks, Patterns, and Templates for Gutenberg Block Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘postBodyCs…
CVE-2026-2688 MEDIUM Patched 6.5 2026-09-02 The HIPAA FORMS WordPress plugin before 3.2.0 contains a hardcoded authentication bypass via a hardcoded parameter alongside all AJAX requests. The server explicitly checks…
CVE-2026-27086 MEDIUM Patched 6.5 2026-09-04 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: fr…
CVE-2026-27347 MEDIUM 5.3 2026-09-04 Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a t…
CVE-2026-27432 MEDIUM Patched 5.4 2026-09-04 Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. Thi…
CVE-2026-2811 MEDIUM Patched 5.4 2026-09-02 The Ajaxify Comments WordPress plugin before 3.2 is vulnerable to HTTP Header Injection due to insufficient input sanitization and output escaping on user-supplied data. Th…
CVE-2026-31020 CRITICAL 9.8 2026-09-04 In DocsGPT 0.15.0 and below, the application provides a custom prompt feature that allows users to define prompt content used during chatbot interactions. This functionalit…
CVE-2026-3174 HIGH 7.5 2026-09-08 The Event Tickets and Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Stripe OAuth return endp…
CVE-2026-31911 MEDIUM 5.5 2026-09-05 libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminat…
CVE-2026-31912 MEDIUM 5.5 2026-09-05 libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset th…
CVE-2026-32480 MEDIUM 5.3 2026-09-04 Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membershi…
CVE-2026-32773 MEDIUM Patched 6.1 2026-09-02 There is a lack of XSS escaping in the Spark History Server prior to 3.5.8 which allows a malicious Spark job to generate arbitrary unescaped frontend code which could lead…
CVE-2026-33197 NONE — 2026-09-08 AMI APTIOV contains a vulnerability in BIOS where a privileged user may cause the “Incomplete List of Disallowed Inputs” by local access. Successful exploitation of this vu…
CVE-2026-33387 MEDIUM 4.6 2026-09-08 A template injection vulnerability was discovered in the Dashboards functionality due to improper validation of an input parameter. An authenticated user with the required …
CVE-2026-33388 HIGH 7.4 2026-09-08 An access control vulnerability was discovered in the Credentials Manager functionality due to insufficient validation of user privileges. A remote authenticated user with …