Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,575 CVEs

CVEs (78,575, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 78,575 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9594 MEDIUM 4.4 2026-06-06 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location…
CVE-2026-9593 MEDIUM 6.7 2026-08-03 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the app…
CVE-2026-9592 NONE — 2026-07-17 SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is …
CVE-2026-9591 NONE — 2026-06-17 Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news item…
CVE-2026-9590 MEDIUM Patched 5.3 2026-06-02 Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify…
CVE-2026-9588 NONE — 2026-07-17 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_…
CVE-2026-9587 NONE — 2026-07-17 An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through …
CVE-2026-9586 CRITICAL Patched 9.8 2026-07-17 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> &hellip;
CVE-2026-9585 NONE &mdash; 2026-07-17 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti&hellip;
CVE-2026-9584 HIGH 7.3 2026-05-26 A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The m&hellip;
CVE-2026-9583 MEDIUM 4.3 2026-05-26 A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of t&hellip;
CVE-2026-9582 MEDIUM 4.3 2026-05-26 A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipula&hellip;
CVE-2026-9581 MEDIUM 6.3 2026-05-26 A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper acces&hellip;
CVE-2026-9580 HIGH 7.3 2026-05-26 A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation &hellip;
CVE-2026-9579 MEDIUM 6.3 2026-05-26 A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The man&hellip;
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?&hellip;
CVE-2026-9576 MEDIUM Patched 4.9 2026-06-30 The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users&hellip;
CVE-2026-9575 HIGH 7.3 2026-05-26 A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.p&hellip;
CVE-2026-9574 HIGH 7.3 2026-05-26 A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Execut&hellip;
CVE-2026-9573 HIGH 7.3 2026-05-26 A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. &hellip;
CVE-2026-9572 LOW Patched 3.3 2026-05-26 A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4&hellip;
CVE-2026-9571 MEDIUM Patched 5.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivat&hellip;
CVE-2026-9568 MEDIUM 5.0 2026-05-26 A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the&hellip;
CVE-2026-9567 LOW 3.3 2026-05-26 A security flaw has been discovered in GPAC up to 2.4.0. Affected is the function MergeFragment of the file src/isomedia/isom_intern.c of the component MP4Box. The manipula&hellip;
CVE-2026-9566 MEDIUM 4.3 2026-05-26 A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the com&hellip;