Search
30,126 CVEs
CVEs (30,126, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 376–400 of 30,126 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86242 | HIGH | Patched | 8.1 | 2026-09-06 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is d… |
| CVE-2026-86212 | MEDIUM | 4.3 | 2026-09-06 | A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. T… | |
| CVE-2026-86205 | MEDIUM | Patched | 5.4 | 2026-09-06 | h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pat… |
| CVE-2022-51009 | HIGH | Patched | 7.5 | 2026-09-06 | PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin pack… |
| CVE-2022-51008 | MEDIUM | Patched | 5.3 | 2026-09-06 | PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers … |
| CVE-2021-48007 | MEDIUM | Patched | 6.5 | 2026-09-06 | PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet… |
| CVE-2021-48006 | LOW | Patched | 3.3 | 2026-09-06 | PocketMine-MP before 4.0.3 does not perform case-insensitive matching when removing operator entries from ops.txt. The removeOp function lowercases the supplied name but on… |
| CVE-2020-37277 | MEDIUM | Patched | 6.5 | 2026-09-06 | PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s… |
| CVE-2026-86211 | HIGH | 7.3 | 2026-09-06 | A flaw has been found in rabindralamsal inventory-management-system 1.0.0. This affects an unknown part of the file index.php of the component Login. Executing a manipulati… | |
| CVE-2026-86210 | HIGH | 7.3 | 2026-09-06 | A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /… | |
| CVE-2026-86209 | HIGH | 7.3 | 2026-09-06 | A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /delete_user.php. This manipulation of t… | |
| CVE-2026-86208 | HIGH | 7.3 | 2026-09-06 | A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulat… | |
| CVE-2026-80439 | MEDIUM | Patched | 4.8 | 2026-09-06 | The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes th… |
| CVE-2026-80437 | MEDIUM | Patched | 4.8 | 2026-09-06 | The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content … |
| CVE-2026-19862 | MEDIUM | Patched | 4.8 | 2026-09-06 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to th… |
| CVE-2026-19859 | MEDIUM | Patched | 6.5 | 2026-09-06 | The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute a… |
| CVE-2026-86183 | MEDIUM | 5.3 | 2026-09-06 | A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.… | |
| CVE-2026-86182 | MEDIUM | 4.3 | 2026-09-06 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.… | |
| CVE-2026-86181 | LOW | 3.5 | 2026-09-06 | A vulnerability was found in code-projects Task Management System 1.0. Affected by this issue is some unknown functionality of the file /user/UpdateUserProfile.php of the c… | |
| CVE-2026-86180 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in code-projects Task Management System In PHP 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the … | |
| CVE-2026-86179 | MEDIUM | 5.3 | 2026-09-06 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Ba… | |
| CVE-2026-86172 | MEDIUM | 6.3 | 2026-09-06 | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argum… | |
| CVE-2026-86171 | MEDIUM | 6.3 | 2026-09-06 | A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the ar… | |
| CVE-2026-85038 | MEDIUM | Patched | 5.3 | 2026-09-06 | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected d… |
| CVE-2026-84219 | HIGH | Patched | 7.5 | 2026-09-06 | The Kirki WordPress plugin before 6.3.0 does not hold back every spelling of the HTML entities it decodes when rendering, allowing unauthenticated users to store JavaScrip… |