Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 78,484 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-84028 | MEDIUM | Patched | 6.8 | 2026-09-06 | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Co… |
| CVE-2026-75793 | MEDIUM | Patched | 6.5 | 2026-09-06 | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to crea… |
| CVE-2026-18480 | HIGH | Patched | 8.8 | 2026-09-06 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use… |
| CVE-2026-13159 | MEDIUM | 4.3 | 2026-09-06 | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscri… | |
| CVE-2026-86170 | MEDIUM | 6.3 | 2026-09-06 | A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argum… | |
| CVE-2026-86168 | HIGH | 7.3 | 2026-09-06 | A security flaw has been discovered in code-projects Content Management System 1.0. The affected element is an unknown function of the file /login.php. The manipulation of … | |
| CVE-2026-86167 | CRITICAL | 9.9 | 2026-09-06 | A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation… | |
| CVE-2026-86166 | HIGH | 8.8 | 2026-09-06 | A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formWanRedirect of the file /boaform/formWanRedirect of the component Boa Web Server… | |
| CVE-2026-86165 | CRITICAL | 9.8 | 2026-09-06 | A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argu… | |
| CVE-2026-86164 | MEDIUM | 6.3 | 2026-09-06 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of t… | |
| CVE-2026-86163 | MEDIUM | 6.3 | 2026-09-06 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argu… | |
| CVE-2026-86218 | NONE | Patched | — | 2026-09-06 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
| CVE-2026-86162 | HIGH | 7.3 | 2026-09-06 | A vulnerability was determined in SourceCodester Online Voting System 1.0. This affects an unknown function of the file /ajax.php?action=login. Executing a manipulation of … | |
| CVE-2026-86161 | HIGH | 7.3 | 2026-09-06 | A vulnerability was found in SourceCodester Online Voting System 1.0. The impacted element is an unknown function of the file /ajax.php?action=delete_category. Performing a… | |
| CVE-2026-86160 | HIGH | 7.3 | 2026-09-06 | A vulnerability has been found in SourceCodester Online Voting System 1.0. The affected element is an unknown function of the file /ajax.php?action=delete_voting. Such mani… | |
| CVE-2026-86159 | HIGH | 7.3 | 2026-09-06 | A flaw has been found in SourceCodester Online Voting System 1.0. Impacted is an unknown function of the file /ajax.php?action=save_user. This manipulation of the argument … | |
| CVE-2026-75816 | CRITICAL | 9.8 | 2026-09-06 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due … | |
| CVE-2026-18056 | HIGH | 7.5 | 2026-09-06 | The HivePress Authentication plugin for WordPress is vulnerable to Authentication Bypass via the access_token parameter in all versions up to, and including, 1.1.4. This is… | |
| CVE-2026-16310 | CRITICAL | 9.8 | 2026-09-06 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing vali… | |
| CVE-2026-86153 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability has been found in Tenda CP3 27.5.57.101. This affects the function CRedirServer::SetRedirectEnable of the file Functions/Redirect.cpp. The manipulation lead… | |
| CVE-2026-86152 | CRITICAL | 10.0 | 2026-09-06 | A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. … | |
| CVE-2026-86151 | CRITICAL | 9.1 | 2026-09-06 | A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Mana… | |
| CVE-2026-86150 | MEDIUM | 4.1 | 2026-09-05 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument … | |
| CVE-2026-76161 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-76160 | NONE | — | 2026-09-05 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |