Search
808 CVEs · Medium severity
CVEs (808, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 808 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85577 | MEDIUM | 5.4 | 2026-09-04 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php that allows unauthenticated attackers to inject arbitrary JavaScrip… | |
| CVE-2026-19043 | MEDIUM | Patched | 4.3 | 2026-09-04 | Missing Authorization vulnerability in Menulux Software Inc. Menulux Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Menulux Por… |
| CVE-2026-18957 | MEDIUM | Patched | 5.4 | 2026-09-04 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Menulux Software Inc. Menulux Portal allows Stored XSS. This issue af… |
| CVE-2026-85534 | MEDIUM | 5.9 | 2026-09-04 | A flaw was found in libsoup. When a client sends an HTTP/2 request body from a non-pollable input stream, the library can buffer more data than the current flow-control win… | |
| CVE-2026-84045 | MEDIUM | Patched | 5.3 | 2026-09-04 | The E-cab Taxi Booking Manager for Woocommerce WordPress plugin before 2.0.5 does not validate a client-supplied trip distance and base-price value on the server before pri… |
| CVE-2026-27347 | MEDIUM | 5.3 | 2026-09-04 | Missing Authorization vulnerability in Crocoblock JetPopup allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects JetPopup: from n/a t… | |
| CVE-2026-85541 | MEDIUM | 5.4 | 2026-09-04 | DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browse… | |
| CVE-2026-84044 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Restaurant Menu and Food Ordering WordPress plugin before 2.4.12 does not verify that a PayPal payment notification genuinely originates from PayPal, allowing unauthent… |
| CVE-2026-84043 | MEDIUM | Patched | 5.3 | 2026-09-04 | The ePayco Payment Gateway for WooCommerce WordPress plugin before 8.4.7 does not properly verify the authenticity of payment confirmation requests, allowing unauthenticate… |
| CVE-2026-81666 | MEDIUM | 6.5 | 2026-09-04 | An integer overflow was found in Corosync's handling of membership commit token messages. The length-validation check for these messages can be bypassed on 32-bit systems d… | |
| CVE-2026-27086 | MEDIUM | Patched | 6.5 | 2026-09-04 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xtemos WoodMart allows DOM-Based XSS. This issue affects WoodMart: fr… |
| CVE-2026-85528 | MEDIUM | 5.3 | 2026-09-04 | Improper input validation of the auto-configuration account identifier in Snowflake JDBC Driver versions 4.2.0 through 4.3.3 allowed a credential-bearing login request to b… | |
| CVE-2026-85311 | MEDIUM | 5.3 | 2026-09-04 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: fro… | |
| CVE-2026-32480 | MEDIUM | 5.3 | 2026-09-04 | Missing Authorization vulnerability in WC Lovers WCFM Membership allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WCFM Membershi… | |
| CVE-2026-27432 | MEDIUM | Patched | 5.4 | 2026-09-04 | Authorization Bypass Through User-Controlled Key vulnerability in sc Internet Vivoo WP Rentals allows Exploiting Incorrectly Configured Access Control Security Levels. Thi… |
| CVE-2026-80190 | MEDIUM | Patched | 6.1 | 2026-09-04 | Apache Allura: stored XSS via SVN code repositories. Git repositories are not known to be affected. The vulnerability is likely mitigated via default CSP headers. This… |
| CVE-2026-6217 | MEDIUM | 6.3 | 2026-09-04 | Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis. This issue affects Pik Online Portal: thro… | |
| CVE-2026-84146 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Xpro Addons — 140+ Widgets for Elementor WordPress plugin before 1.7.8 does not perform any capability or post-status check before rendering a WooCommerce product summa… |
| CVE-2026-82194 | MEDIUM | Patched | 5.5 | 2026-09-04 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied path before using it in a file deletion routine, allowing admini… |
| CVE-2026-82193 | MEDIUM | Patched | 5.5 | 2026-09-04 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.134 does not validate a user supplied file name before using it to build a write path, allowing admini… |
| CVE-2026-82186 | MEDIUM | Patched | 4.1 | 2026-09-04 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator p… |
| CVE-2026-81347 | MEDIUM | Patched | 5.9 | 2026-09-04 | The Frontend Admin by DynamiApps WordPress plugin before 3.29.13 does not properly validate a user-controllable directory path before deleting files within it, allowing una… |
| CVE-2026-80438 | MEDIUM | Patched | 5.9 | 2026-09-04 | The Ninja Forms WordPress plugin before 3.15.2 does not restrict its REST abilities to administrators, accepting a Ninja Forms WordPress plugin before 3.15.2-specific cap… |
| CVE-2026-80180 | MEDIUM | Patched | 6.1 | 2026-09-04 | Stored XSS via markdown HTML processing in Apache Allura. This issue affects Apache Allura: from through 1.20.0. Users are recommended to upgrade to version 1.21.0, w… |
| CVE-2026-79632 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not perform any authorisation or nonce check in one of its opt-in submission handlers, and takes the notification recipie… |