Search
158,556 CVEs · Medium severity
CVEs (158,556, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 158,556 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8689 | MEDIUM | 4.3 | 2026-05-28 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is d… | |
| CVE-2026-8688 | MEDIUM | 4.3 | 2026-06-24 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve… | |
| CVE-2026-8685 | MEDIUM | 6.5 | 2026-05-20 | The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due … | |
| CVE-2026-8684 | MEDIUM | 5.3 | 2026-05-22 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly v… | |
| CVE-2026-8683 | MEDIUM | Patched | 6.5 | 2026-06-15 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owne… |
| CVE-2026-8682 | MEDIUM | 4.3 | 2026-05-28 | The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1.… | |
| CVE-2026-8681 | MEDIUM | 5.3 | 2026-05-16 | The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly ve… | |
| CVE-2026-8678 | MEDIUM | 4.3 | 2026-07-11 | The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that … | |
| CVE-2026-8677 | MEDIUM | 6.4 | 2026-06-09 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings i… | |
| CVE-2026-8673 | MEDIUM | Patched | 5.9 | 2026-05-22 | Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0. |
| CVE-2026-8672 | MEDIUM | Patched | 5.1 | 2026-05-22 | Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: be… |
| CVE-2026-8669 | MEDIUM | 6.5 | 2026-05-15 | Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single … | |
| CVE-2026-8664 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host para… |
| CVE-2026-8663 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name p… |
| CVE-2026-8661 | MEDIUM | 4.8 | 2026-06-26 | Server-Side Cross-Site Scripting and Server-Side Request Forgery vulnerability in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin version 3.1.4 and earl… | |
| CVE-2026-8659 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_p… |
| CVE-2026-8658 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filte… |
| CVE-2026-8656 | MEDIUM | Patched | 6.1 | 2026-05-16 | Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and … |
| CVE-2026-8653 | MEDIUM | 6.5 | 2026-06-04 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to ins… | |
| CVE-2026-8650 | MEDIUM | Patched | 4.5 | 2026-07-08 | Relative path traversal vulnerability in Progress MOVEit Transfer (Admin Settings module). This issue affects MOVEit Transfer: before 2025.0.7, from 2025.1.0 before 2025.1.3. |
| CVE-2026-8649 | MEDIUM | Patched | 6.4 | 2026-07-08 | Improper Neutralization of Special Elements in Data Query Logic vulnerability in Progress MOVEit Transfer (Custom Reports modules). This issue affects MOVEit Transfer: bef… |
| CVE-2026-8647 | MEDIUM | 4.8 | 2026-05-26 | Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the bu… | |
| CVE-2026-8643 | MEDIUM | Patched | 5.5 | 2026-06-01 | pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry… |
| CVE-2026-8636 | MEDIUM | 5.5 | 2026-06-22 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 allows an attacker to retrieve user passwords and cryptographic keys from memory. Atta… | |
| CVE-2026-8628 | MEDIUM | 6.1 | 2026-06-24 | The EntreDroppers plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 1.1.2 due to insufficien… |