Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8804 | NONE | Patched | — | 2026-07-03 | Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, … |
| CVE-2026-8801 | LOW | Patched | 3.5 | 2026-07-08 | Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4. |
| CVE-2026-8800 | LOW | Patched | 2.7 | 2026-07-08 | Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| CVE-2026-8798 | NONE | — | 2026-08-08 | In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSE… | |
| CVE-2026-8797 | NONE | — | 2026-06-26 | An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with… | |
| CVE-2026-8794 | NONE | — | 2026-08-03 | PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform usern… | |
| CVE-2026-8793 | NONE | — | 2026-08-03 | PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to… | |
| CVE-2026-8791 | MEDIUM | 6.4 | 2026-07-29 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17… | |
| CVE-2026-8790 | MEDIUM | 6.1 | 2026-08-05 | The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and … | |
| CVE-2026-8789 | HIGH | 8.1 | 2026-07-24 | The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_de… | |
| CVE-2026-8763 | CRITICAL | Patched | 9.1 | 2026-08-03 | In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, an… |
| CVE-2026-8761 | HIGH | 8.8 | 2026-08-05 | The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `Custo… | |
| CVE-2026-8720 | HIGH | Patched | 7.5 | 2026-06-25 | wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the suppl… |
| CVE-2026-8718 | HIGH | 8.4 | 2026-08-10 | tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied … | |
| CVE-2026-8717 | NONE | — | 2026-08-20 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-8715 | CRITICAL | Patched | 9.6 | 2026-08-13 | Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allo… |
| CVE-2026-8713 | CRITICAL | 9.1 | 2026-06-19 | The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all … | |
| CVE-2026-8712 | HIGH | Patched | 8.3 | 2026-09-01 | Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr… |
| CVE-2026-8709 | CRITICAL | Patched | 9.9 | 2026-08-05 | An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user w… |
| CVE-2026-8705 | HIGH | 7.5 | 2026-06-24 | The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions… | |
| CVE-2026-8699 | NONE | — | 2026-07-02 | A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side valid… | |
| CVE-2026-8694 | MEDIUM | Patched | 5.3 | 2026-06-12 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defin… |
| CVE-2026-8690 | MEDIUM | 5.3 | 2026-06-24 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the p… | |
| CVE-2026-8688 | MEDIUM | 4.3 | 2026-06-24 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve… | |
| CVE-2026-8683 | MEDIUM | Patched | 6.5 | 2026-06-15 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owne… |