Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

158,556 CVEs · Medium severity

CVEs (158,556, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 158,556 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8689 MEDIUM 4.3 2026-05-28 The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is d…
CVE-2026-8688 MEDIUM 4.3 2026-06-24 The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve…
CVE-2026-8685 MEDIUM 6.5 2026-05-20 The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due …
CVE-2026-8684 MEDIUM 5.3 2026-05-22 The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly v…
CVE-2026-8683 MEDIUM Patched 6.5 2026-06-15 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owne&hellip;
CVE-2026-8682 MEDIUM 4.3 2026-05-28 The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1.&hellip;
CVE-2026-8681 MEDIUM 5.3 2026-05-16 The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly ve&hellip;
CVE-2026-8678 MEDIUM 4.3 2026-07-11 The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that &hellip;
CVE-2026-8677 MEDIUM 6.4 2026-06-09 The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings i&hellip;
CVE-2026-8673 MEDIUM Patched 5.9 2026-05-22 Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.
CVE-2026-8672 MEDIUM Patched 5.1 2026-05-22 Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: be&hellip;
CVE-2026-8669 MEDIUM 6.5 2026-05-15 Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single &hellip;
CVE-2026-8664 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host para&hellip;
CVE-2026-8663 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name p&hellip;
CVE-2026-8661 MEDIUM 4.8 2026-06-26 Server-Side Cross-Site Scripting and Server-Side Request Forgery vulnerability in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin version 3.1.4 and earl&hellip;
CVE-2026-8659 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_p&hellip;
CVE-2026-8658 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filte&hellip;
CVE-2026-8656 MEDIUM Patched 6.1 2026-05-16 Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and &hellip;
CVE-2026-8653 MEDIUM 6.5 2026-06-04 The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to ins&hellip;
CVE-2026-8650 MEDIUM Patched 4.5 2026-07-08 Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3.
CVE-2026-8649 MEDIUM Patched 6.4 2026-07-08 Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: bef&hellip;
CVE-2026-8647 MEDIUM 4.8 2026-05-26 Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the bu&hellip;
CVE-2026-8643 MEDIUM Patched 5.5 2026-06-01 pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry&hellip;
CVE-2026-8636 MEDIUM 5.5 2026-06-22 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Atta&hellip;
CVE-2026-8628 MEDIUM 6.1 2026-06-24 The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficien&hellip;