Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8866 | MEDIUM | 6.4 | 2026-05-27 | The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This i… | |
| CVE-2026-8865 | MEDIUM | 6.4 | 2026-06-24 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and in… | |
| CVE-2026-8861 | MEDIUM | Patched | 5.3 | 2026-07-17 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information coul… |
| CVE-2026-8853 | MEDIUM | 4.4 | 2026-06-10 | The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient in… | |
| CVE-2026-8852 | MEDIUM | Patched | 6.2 | 2026-05-26 | IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module. |
| CVE-2026-8847 | MEDIUM | 6.4 | 2026-05-27 | The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input sanitizatio… | |
| CVE-2026-8846 | MEDIUM | 6.4 | 2026-05-27 | The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due to insufficie… | |
| CVE-2026-8845 | MEDIUM | 6.4 | 2026-05-27 | The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is du… | |
| CVE-2026-8844 | MEDIUM | 6.4 | 2026-05-27 | The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is due to … | |
| CVE-2026-8843 | MEDIUM | 6.5 | 2026-05-18 | Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index wi… | |
| CVE-2026-8842 | MEDIUM | 6.4 | 2026-05-27 | The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This is due… | |
| CVE-2026-8841 | MEDIUM | 6.4 | 2026-06-09 | The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, an… | |
| CVE-2026-8840 | MEDIUM | 5.3 | 2026-08-15 | The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the… | |
| CVE-2026-8839 | MEDIUM | 5.3 | 2026-06-06 | The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is… | |
| CVE-2026-8837 | MEDIUM | 6.4 | 2026-05-27 | The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and in… | |
| CVE-2026-8833 | MEDIUM | 5.4 | 2026-06-08 | Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated … | |
| CVE-2026-8830 | MEDIUM | 4.3 | 2026-05-19 | A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occu… | |
| CVE-2026-8825 | MEDIUM | Patched | 4.9 | 2026-07-20 | The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing… |
| CVE-2026-8814 | MEDIUM | Patched | 5.3 | 2026-05-19 | Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata w… |
| CVE-2026-8810 | MEDIUM | 6.9 | 2026-08-19 | On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables. | |
| CVE-2026-8802 | MEDIUM | 4.3 | 2026-05-18 | A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The … | |
| CVE-2026-8791 | MEDIUM | 6.4 | 2026-07-29 | The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17… | |
| CVE-2026-8790 | MEDIUM | 6.1 | 2026-08-05 | The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and … | |
| CVE-2026-8786 | MEDIUM | Patched | 6.3 | 2026-05-18 | A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initial… |
| CVE-2026-8784 | MEDIUM | 4.2 | 2026-05-18 | A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in syml… |