Search
808 CVEs · Medium severity
CVEs (808, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 351–375 of 808 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19727 | MEDIUM | 6.1 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Syst… | |
| CVE-2026-14466 | MEDIUM | 4.3 | 2026-09-04 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject … | |
| CVE-2026-85522 | MEDIUM | 5.3 | 2026-09-04 | A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Affected by this vulnerability is the function createSlotImportJob of the file src/cluster_migrateslots.… | |
| CVE-2026-85517 | MEDIUM | 5.3 | 2026-09-04 | A flaw has been found in code-projects Vehicle Management System 1.0. The impacted element is an unknown function of the file /vehicle_management.sql of the component SQL D… | |
| CVE-2026-77818 | MEDIUM | 6.1 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Syst… | |
| CVE-2026-19081 | MEDIUM | Patched | 4.3 | 2026-09-04 | Missing Authorization vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affect… |
| CVE-2026-19057 | MEDIUM | Patched | 5.4 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gastromenum Gastromenum Ticket and QR Menu System allows Stored XSS. … |
| CVE-2026-85514 | MEDIUM | 6.3 | 2026-09-04 | A security vulnerability has been detected in StackStorm st2 up to 3.9.0. Impacted is an unknown function of the file st2api/st2api/controllers/v1/auth.py of the component … | |
| CVE-2026-85513 | MEDIUM | 6.3 | 2026-09-04 | A weakness has been identified in StackStorm st2 up to 3.9.0. This issue affects the function assert_user_is_admin_if_user_query_param_is_provided of the file st2api/st2api… | |
| CVE-2026-74237 | MEDIUM | Patched | 6.5 | 2026-09-04 | GFI Exinda AI and ClearView before 7.6.5 contains an argument injection vulnerability in the Tools Iperf Client functionality. The web_tools_cmd() function constructs an ip… |
| CVE-2026-74236 | MEDIUM | Patched | 6.5 | 2026-09-04 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the diagnostic file deletion handler. The unlink_or_email_file() function accepts parame… |
| CVE-2026-74235 | MEDIUM | Patched | 4.9 | 2026-09-04 | GFI Exinda AI and ClearView before 7.6.5 contains a path traversal vulnerability in the system maintenance configuration download handler. The wcf_handle_download() functio… |
| CVE-2026-85615 | MEDIUM | Patched | 6.4 | 2026-09-04 | Openpanel before 2.3.0 contains an insecure direct object reference vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to bind dashboar… |
| CVE-2026-85611 | MEDIUM | Patched | 6.4 | 2026-09-04 | OpenPanel before 2.3.0 contains a cross-tenant broken object level authorization vulnerability in the report.getLayouts and report.resetLayout tRPC procedures that fail to … |
| CVE-2026-85603 | MEDIUM | Patched | 6.5 | 2026-09-04 | Grav versions before 1.10.55 contain a path traversal vulnerability in the admin plugin's Save As action that fails to validate the language code parameter. An authenticate… |
| CVE-2026-85602 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Grav Form plugin (getgrav/grav-plugin-form) versions 8.0.6 through 9.1.19 select the reCAPTCHA version to validate based solely on which response field key is present i… |
| CVE-2026-85601 | MEDIUM | Patched | 5.4 | 2026-09-04 | Grav Admin before 2.0.20 fails to sanitize output from marked.parse() before injecting it into the DOM via Svelte's {@html} directive in MarkdownEditor and MarkdownModal co… |
| CVE-2026-85600 | MEDIUM | Patched | 5.4 | 2026-09-04 | Grav Admin (getgrav/grav-plugin-admin2) versions <= 2.0.19 contain a stored cross-site scripting vulnerability in the tHtml() function (src/lib/stores/i18n.svelte.ts), whic… |
| CVE-2026-85598 | MEDIUM | 6.4 | 2026-09-04 | Grav versions 2.0.0 through 2.0.17 fail to apply save-time XSS detection to modular pages, allowing authenticated page editors to store Twig-assembled XSS payloads. Attacke… | |
| CVE-2026-85593 | MEDIUM | Patched | 5.4 | 2026-09-04 | phpMyFAQ versions before 4.1.8 contain a stored cross-site scripting vulnerability in FaqHelper::convertOldInternalLinks() that calls html_entity_decode() on sanitized FAQ … |
| CVE-2026-85583 | MEDIUM | 6.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain a path traversal vulnerability in the reader-accessible file-read endpoint that follows symlinks when opening authorized asset paths. … | |
| CVE-2026-85582 | MEDIUM | 6.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain an unbounded session creation vulnerability in the publish-service Basic Auth handler that allows authenticated attackers to exhaust m… | |
| CVE-2026-85580 | MEDIUM | 6.5 | 2026-09-04 | SiYuan versions before v3.8.2 contain a path guard bypass vulnerability in the MCP file-access handler that uses case-sensitive matching on Linux filesystems. Attackers can… | |
| CVE-2026-85579 | MEDIUM | Patched | 4.3 | 2026-09-04 | SiYuan is affected by an information disclosure vulnerability (confirmed in v3.8.1, fixed in v3.8.2) in the reader-accessible POST /api/transactions/undoState endpoint. The… |
| CVE-2026-85578 | MEDIUM | 6.5 | 2026-09-04 | SiYuan through 3.8.1 contains an authorization bypass vulnerability in the /api/file/getFile endpoint that allows readers to retrieve files from notebooks explicitly config… |