Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 163,528 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71216 | MEDIUM | Patched | 5.3 | 2026-09-04 | PagerDuty alarm hook transmits the integration routing key over cleartext HTTP. PagerDuty serves this endpoint over HTTPS and will normally answer plain HTTP with a redi… |
| CVE-2026-74853 | MEDIUM | Patched | 6.8 | 2026-09-04 | The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitra… |
| CVE-2026-79630 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not verify that the product requested through a checkout order bump is the product that bump's discount was configured fo… |
| CVE-2026-79631 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not restrict access to the log files it writes to a predictable location under the public uploads directory, allowing una… |
| CVE-2026-17517 | MEDIUM | Patched | 5.3 | 2026-09-04 | The Content Views WordPress plugin before 4.5.1.2 does not check whether the user requesting a view is allowed to read the posts it returns, allowing unauthenticated attac… |
| CVE-2025-15691 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying… |
| CVE-2026-85407 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was found in Eleveo Quality Management 9.7.0. This issue affects some unknown processing of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the c… | |
| CVE-2026-85408 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was determined in Eleveo Quality Management 9.7.0. Impacted is an unknown function of the file /enc-fwk-data/api/v3/conversations/<ID>/events of the compone… | |
| CVE-2026-85409 | MEDIUM | 6.3 | 2026-09-04 | A vulnerability was identified in Eleveo Quality Management 9.7.0. The affected element is the function QuestionnaireService.runDataExportNow of the component Questionnaire… | |
| CVE-2026-85149 | MEDIUM | 5.3 | 2026-09-04 | SmartIT Desktop Manager developed by Lightstar has a Use of Hard-coded Credentials vulnerability. Unauthenticated remote attackers can obtain the SFTP service credentials o… | |
| CVE-2026-85401 | MEDIUM | 6.3 | 2026-09-04 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connector… | |
| CVE-2026-85382 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d… | |
| CVE-2026-85383 | MEDIUM | 6.3 | 2026-09-04 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation o… | |
| CVE-2026-85381 | MEDIUM | 5.3 | 2026-09-04 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unkno… | |
| CVE-2026-49509 | MEDIUM | 4.4 | 2026-09-04 | Out-of-bounds read vulnerability in Samsung Opensource rLottie allows Overread Buffers. This issue affects rLottie: 25648aef19187b3f87f4d9420b8d761453ad4630. | |
| CVE-2026-85453 | MEDIUM | 6.1 | 2026-09-03 | MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set… | |
| CVE-2026-85454 | MEDIUM | 6.1 | 2026-09-03 | MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stac… | |
| CVE-2026-85456 | MEDIUM | 5.5 | 2026-09-03 | MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directo… | |
| CVE-2026-85241 | MEDIUM | 6.3 | 2026-09-03 | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the com… | |
| CVE-2026-9036 | MEDIUM | 5.9 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv… | |
| CVE-2026-9736 | MEDIUM | 5.3 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements w… | |
| CVE-2026-9744 | MEDIUM | 5.3 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv… | |
| CVE-2026-9745 | MEDIUM | 6.5 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This om… | |
| CVE-2026-82521 | MEDIUM | Patched | 5.3 | 2026-09-03 | parsedmarc 9.0.6 before 11.0.1 writes forensic report sample files using an output path derived from the email subject. When the subject consists entirely of path traversal… |
| CVE-2026-84185 | MEDIUM | 5.9 | 2026-09-03 | A flaw was found in the jwcrypto library, which is used for implementing Javascript Object Signing and Encryption (JOSE) standards. The issue occurs when the library verifi… |