Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,503 CVEs · Medium severity

CVEs (163,503, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 376–400 of 163,503 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84146 MEDIUM Patched 5.3 2026-09-04 The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summa…
CVE-2026-82194 MEDIUM Patched 5.5 2026-09-04 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing admini…
CVE-2026-82193 MEDIUM Patched 5.5 2026-09-04 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing admini…
CVE-2026-82186 MEDIUM Patched 4.1 2026-09-04 The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator p…
CVE-2026-81347 MEDIUM Patched 5.9 2026-09-04 The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing una…
CVE-2026-80438 MEDIUM Patched 5.9 2026-09-04 The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific cap…
CVE-2026-80180 MEDIUM Patched 6.1 2026-09-04 Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, w…
CVE-2026-79632 MEDIUM Patched 5.3 2026-09-04 The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipie…
CVE-2026-79631 MEDIUM Patched 5.3 2026-09-04 The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing una…
CVE-2026-79630 MEDIUM Patched 5.3 2026-09-04 The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured fo…
CVE-2026-74853 MEDIUM Patched 6.8 2026-09-04 The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitra…
CVE-2026-17517 MEDIUM Patched 5.3 2026-09-04 The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attac…
CVE-2025-15691 MEDIUM Patched 5.3 2026-09-04 The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying…
CVE-2026-85409 MEDIUM 6.3 2026-09-04 A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire…
CVE-2026-85408 MEDIUM 4.3 2026-09-04 A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the compone&hellip;
CVE-2026-85407 MEDIUM 4.3 2026-09-04 A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the c&hellip;
CVE-2026-85401 MEDIUM 6.3 2026-09-04 A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connector&hellip;
CVE-2026-85149 MEDIUM 5.3 2026-09-04 SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials o&hellip;
CVE-2026-85383 MEDIUM 6.3 2026-09-04 A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation o&hellip;
CVE-2026-85382 MEDIUM 4.3 2026-09-04 A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d&hellip;
CVE-2026-85381 MEDIUM 5.3 2026-09-04 A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unkno&hellip;
CVE-2026-49509 MEDIUM 4.4 2026-09-04 Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630.
CVE-2026-85456 MEDIUM 5.5 2026-09-03 MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directo&hellip;
CVE-2026-85454 MEDIUM 6.1 2026-09-03 MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stac&hellip;
CVE-2026-85453 MEDIUM 6.1 2026-09-03 MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set&hellip;