Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8866 MEDIUM 6.4 2026-05-27 The jQuery googleslides plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'googleslides' shortcode in all versions up to, and including, 1.3. This i…
CVE-2026-8865 MEDIUM 6.4 2026-06-24 The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and in…
CVE-2026-8861 MEDIUM Patched 5.3 2026-07-17 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information coul…
CVE-2026-8853 MEDIUM 4.4 2026-06-10 The MW WP Form plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'memo' parameter in all versions up to, and including, 5.1.3 due to insufficient in…
CVE-2026-8852 MEDIUM Patched 6.2 2026-05-26 IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
CVE-2026-8847 MEDIUM 6.4 2026-05-27 The Dideo plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'dideo' shortcode in version 1.0. This is due to insufficient input sanitizatio…
CVE-2026-8846 MEDIUM 6.4 2026-05-27 The Tuxquote plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'TUXQUOTE' shortcode in versions up to, and including, 1.3. This is due to insufficie…
CVE-2026-8845 MEDIUM 6.4 2026-05-27 The Islamic Database plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'islamicDB-roqya' shortcode in versions up to, and including, 1.0. This is du…
CVE-2026-8844 MEDIUM 6.4 2026-05-27 The Responsive Check plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rspcheck' shortcode in versions up to, and including, 0.0.3. This is due to …
CVE-2026-8843 MEDIUM 6.5 2026-05-18 Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index wi…
CVE-2026-8842 MEDIUM 6.4 2026-05-27 The Google+ Link Name plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gplusnamelink' shortcode in versions up to, and including, 1.0. This is due…
CVE-2026-8841 MEDIUM 6.4 2026-06-09 The Extra Settings for RocketChat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'rocketchat' shortcode's 'title' attribute in versions up to, an…
CVE-2026-8840 MEDIUM 5.3 2026-08-15 The Booking calendar, Appointment Booking System plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.2.36. This is due to the…
CVE-2026-8839 MEDIUM 5.3 2026-06-06 The MapPress Maps for WordPress plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.96.6. This is…
CVE-2026-8837 MEDIUM 6.4 2026-05-27 The WP Iframe Geo Style for Amazon affiliates plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'adid' Shortcode Attribute in all versions up to, and in…
CVE-2026-8833 MEDIUM 5.4 2026-06-08 Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated &hellip;
CVE-2026-8830 MEDIUM 4.3 2026-05-19 A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occu&hellip;
CVE-2026-8825 MEDIUM Patched 4.9 2026-07-20 The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing&hellip;
CVE-2026-8814 MEDIUM Patched 5.3 2026-05-19 Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata w&hellip;
CVE-2026-8810 MEDIUM 6.9 2026-08-19 On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
CVE-2026-8802 MEDIUM 4.3 2026-05-18 A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The &hellip;
CVE-2026-8791 MEDIUM 6.4 2026-07-29 The Booking System Trafft plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `bookingWebsiteUrl` setting in all versions up to, and including, 1.0.17&hellip;
CVE-2026-8790 MEDIUM 6.1 2026-08-05 The Football Pool plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the `shouttext` POST parameter of the Shoutbox widget in all versions up to, and &hellip;
CVE-2026-8786 MEDIUM Patched 6.3 2026-05-18 A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initial&hellip;
CVE-2026-8784 MEDIUM 4.2 2026-05-18 A vulnerability was detected in npitre cramfs-tools up to 2.2. Affected is the function change_file_status of the file cramfsck.c. Performing a manipulation results in syml&hellip;