Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 351–375 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8678 MEDIUM 4.3 2026-07-11 The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that …
CVE-2026-86714 MEDIUM 5.4 2026-09-08 PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply…
CVE-2026-86713 HIGH 7.1 2026-09-08 PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe…
CVE-2026-86712 HIGH Patched 8.8 2026-09-08 SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de…
CVE-2026-86711 HIGH Patched 7.4 2026-09-08 electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc…
CVE-2026-8668 NONE — 2026-06-18 A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues.  Queue messages contained tenant-specific identifiers.…
CVE-2026-8667 MEDIUM Patched 4.3 2026-08-12 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou…
CVE-2026-86665 HIGH 7.3 2026-09-08 A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation lea…
CVE-2026-8666 HIGH Patched 7.7 2026-06-25 OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via…
CVE-2026-8665 HIGH Patched 7.7 2026-06-25 OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text…
CVE-2026-86644 LOW 3.5 2026-09-08 A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API…
CVE-2026-8664 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host para…
CVE-2026-8663 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name p…
CVE-2026-8662 LOW Patched 3.3 2026-06-25 Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file …
CVE-2026-8661 MEDIUM Patched 4.8 2026-06-26 Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbit…
CVE-2026-8660 HIGH Patched 7.7 2026-06-25 OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host pa…
CVE-2026-86597 MEDIUM 6.5 2026-09-08 Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti…
CVE-2026-86590 NONE Patched — 2026-09-08 In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP…
CVE-2026-8659 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_p…
CVE-2026-8658 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filte…
CVE-2026-86550 MEDIUM 6.5 2026-09-08 NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul…
CVE-2026-8655 CRITICAL Patched 9.8 2026-06-30 Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is con…
CVE-2026-86544 HIGH Patched 8.1 2026-09-07 knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r…
CVE-2026-86543 CRITICAL Patched 9.8 2026-09-07 knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack…
CVE-2026-86542 CRITICAL Patched 9.1 2026-09-07 knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup…