Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8804 NONE Patched — 2026-07-03 Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, …
CVE-2026-8801 LOW Patched 3.5 2026-07-08 Path equivalence: vulnerability in Progress MOVEit Transfer (File Upload modules). This issue affects MOVEit Transfer: before 2025.0.8, from 2025.1.0 before 2025.1.4.
CVE-2026-8800 LOW Patched 2.7 2026-07-08 Incorrect Authorization vulnerability in Progress MOVEit Transfer (Audit User module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-8798 NONE — 2026-08-08 In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, the native entropy source used on Intel platforms retried the CPU entropy instructions without any bound. RDSE…
CVE-2026-8797 NONE — 2026-06-26 An access control deficiency vulnerability exists in ExpressUpdate Agent for Windows. If a malicious user gains access to the product, arbitrary code could be executed with…
CVE-2026-8794 NONE — 2026-08-03 PaperCut NG/MF contains an observable timing discrepancy in its authentication component. An unauthenticated remote attacker can exploit this vulnerability to perform usern…
CVE-2026-8793 NONE — 2026-08-03 PaperCut NG/MF does not properly restrict excessive authentication attempts within its login component. An unauthenticated remote attacker can exploit this vulnerability to…
CVE-2026-8791 MEDIUM 6.4 2026-07-29 The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17…
CVE-2026-8790 MEDIUM 6.1 2026-08-05 The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and …
CVE-2026-8789 HIGH 8.1 2026-07-24 The Easy Appointments plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the `ea_de…
CVE-2026-8763 CRITICAL Patched 9.1 2026-08-03 In Bouncy Castle for Java before 1.85, Name Constraints bypass via trailing dot in rfc822Name and URI. This issue also affects Bouncy Castle for Java LTS before 2.73.12, an…
CVE-2026-8761 HIGH 8.8 2026-08-05 The Dokan plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.0.1. This is due to a missing authorization check in the `Custo…
CVE-2026-8720 HIGH Patched 7.5 2026-06-25 wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the suppl…
CVE-2026-8718 HIGH 8.4 2026-08-10 tls_opt_dtls_peer_connection_id_value_get() in subsys/net/lib/sockets/sockets_tls.c, which handles getsockopt(SOL_TLS, TLS_DTLS_PEER_CID_VALUE), passed the caller-supplied …
CVE-2026-8717 NONE — 2026-08-20 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-8715 CRITICAL Patched 9.6 2026-08-13 Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary file read and credential exfiltration issue in the AppRole authentication configuration that may allo…
CVE-2026-8713 CRITICAL 9.1 2026-06-19 The Avada (Fusion) Builder plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the maybe_delete_files function in all …
CVE-2026-8712 HIGH Patched 8.3 2026-09-01 Wyoming before 1.10.2 contains a server-side request forgery vulnerability that allows unauthenticated attackers with network access to force outbound connections to arbitr…
CVE-2026-8709 CRITICAL Patched 9.9 2026-08-05 An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user w…
CVE-2026-8705 HIGH 7.5 2026-06-24 The ClearSale Total plugin for WordPress is vulnerable to SQL Injection via the `pagseguro[metodo]` POST parameter of the `clearsale_total_push` AJAX action in all versions…
CVE-2026-8699 NONE — 2026-07-02 A stored Cross-Site Scripting (XSS) vulnerability has been identified in the web-based management interface of Archer C5 v6.8 routers, due to insufficient server-side valid…
CVE-2026-8694 MEDIUM Patched 5.3 2026-06-12 Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defin…
CVE-2026-8690 MEDIUM 5.3 2026-06-24 The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the p…
CVE-2026-8688 MEDIUM 4.3 2026-06-24 The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve…
CVE-2026-8683 MEDIUM Patched 6.5 2026-06-15 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owne&hellip;