Search
163,503 CVEs · Medium severity
CVEs (163,503, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 163,503 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84146 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summa… |
| CVE-2026-82194 | MEDIUM | Patched | 5.5 | 2026-09-04 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing admini… |
| CVE-2026-82193 | MEDIUM | Patched | 5.5 | 2026-09-04 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing admini… |
| CVE-2026-82186 | MEDIUM | Patched | 4.1 | 2026-09-04 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator p… |
| CVE-2026-81347 | MEDIUM | Patched | 5.9 | 2026-09-04 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing una… |
| CVE-2026-80438 | MEDIUM | Patched | 5.9 | 2026-09-04 | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific cap… |
| CVE-2026-80180 | MEDIUM | Patched | 6.1 | 2026-09-04 | Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, w… |
| CVE-2026-79632 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipie… |
| CVE-2026-79631 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing una… |
| CVE-2026-79630 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured fo… |
| CVE-2026-74853 | MEDIUM | Patched | 6.8 | 2026-09-04 | The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitra… |
| CVE-2026-17517 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attac… |
| CVE-2025-15691 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying… |
| CVE-2026-85409 | MEDIUM | 6.3 | 2026-09-04 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire… | |
| CVE-2026-85408 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the compone… | |
| CVE-2026-85407 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the c… | |
| CVE-2026-85401 | MEDIUM | 6.3 | 2026-09-04 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connector… | |
| CVE-2026-85149 | MEDIUM | 5.3 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials o… | |
| CVE-2026-85383 | MEDIUM | 6.3 | 2026-09-04 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation o… | |
| CVE-2026-85382 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d… | |
| CVE-2026-85381 | MEDIUM | 5.3 | 2026-09-04 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unkno… | |
| CVE-2026-49509 | MEDIUM | 4.4 | 2026-09-04 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | |
| CVE-2026-85456 | MEDIUM | 5.5 | 2026-09-03 | MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directo… | |
| CVE-2026-85454 | MEDIUM | 6.1 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stac… | |
| CVE-2026-85453 | MEDIUM | 6.1 | 2026-09-03 | MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set… |