Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8678 | MEDIUM | 4.3 | 2026-07-11 | The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that … | |
| CVE-2026-86714 | MEDIUM | 5.4 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply… | |
| CVE-2026-86713 | HIGH | 7.1 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in the load_mon module's stop path where exit_and_cleanup() deletes the LoadMon object and frees the pe… | |
| CVE-2026-86712 | HIGH | Patched | 8.8 | 2026-09-08 | SiYuan before 3.8.2 trusts the attacker-writable text/siyuan clipboard MIME type and skips sanitization in the paste handler, allowing code execution in the Node-enabled de… |
| CVE-2026-86711 | HIGH | Patched | 7.4 | 2026-09-08 | electerm before 5.3.15 exposes 40+ main-process functions through an unvalidated Electron IPC handler with no function-name allowlist or sender validation. Renderer-side sc… |
| CVE-2026-8668 | NONE | — | 2026-06-18 | A static credential embedded in Chef 360 prior to v1.7.0 permitted unauthenticated access to internal message queues. Queue messages contained tenant-specific identifiers.… | |
| CVE-2026-8667 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou… |
| CVE-2026-86665 | HIGH | 7.3 | 2026-09-08 | A vulnerability was identified in aircheng-org iWebShop-5 up to 5.15. This issue affects the function Update::index of the file controllers/update.php. The manipulation lea… | |
| CVE-2026-8666 | HIGH | Patched | 7.7 | 2026-06-25 | OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via… |
| CVE-2026-8665 | HIGH | Patched | 7.7 | 2026-06-25 | OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text… |
| CVE-2026-86644 | LOW | 3.5 | 2026-09-08 | A vulnerability was determined in star7th showdoc up to 3.9.1. This vulnerability affects unknown code of the file web_src/public/editor.md/editormd.js of the component API… | |
| CVE-2026-8664 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host para… |
| CVE-2026-8663 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name p… |
| CVE-2026-8662 | LOW | Patched | 3.3 | 2026-06-25 | Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file … |
| CVE-2026-8661 | MEDIUM | Patched | 4.8 | 2026-06-26 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbit… |
| CVE-2026-8660 | HIGH | Patched | 7.7 | 2026-06-25 | OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host pa… |
| CVE-2026-86597 | MEDIUM | 6.5 | 2026-09-08 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti… | |
| CVE-2026-86590 | NONE | Patched | — | 2026-09-08 | In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend's POST /dashboard/api/data/resolver endpoint passes a caller-supplied URL directly to an outbound HTTP… |
| CVE-2026-8659 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_p… |
| CVE-2026-8658 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filte… |
| CVE-2026-86550 | MEDIUM | 6.5 | 2026-09-08 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul… | |
| CVE-2026-8655 | CRITICAL | Patched | 9.8 | 2026-06-30 | Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is con… |
| CVE-2026-86544 | HIGH | Patched | 8.1 | 2026-09-07 | knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with r… |
| CVE-2026-86543 | CRITICAL | Patched | 9.8 | 2026-09-07 | knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attack… |
| CVE-2026-86542 | CRITICAL | Patched | 9.1 | 2026-09-07 | knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can sup… |