Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8737 | MEDIUM | 5.3 | 2026-05-17 | A weakness has been identified in Sanluan PublicCMS 5.202506.d. This issue affects the function execute of the file publiccms-trade/src/main/java/com/publiccms/views/direct… | |
| CVE-2026-8736 | MEDIUM | 4.1 | 2026-05-17 | A security flaw has been discovered in Oinone Pamirs up to 7.2.0. This vulnerability affects the function request.getParameter of the file LocalFileClient.java of the compo… | |
| CVE-2026-8735 | MEDIUM | 6.3 | 2026-05-17 | A vulnerability was identified in Oinone Pamirs up to 7.2.0. This affects the function JsonUtils.parseMap of the file PamirsParserConfig.java of the component appConfigQuer… | |
| CVE-2026-8733 | MEDIUM | 6.3 | 2026-05-17 | A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulat… | |
| CVE-2026-8731 | MEDIUM | Patched | 4.3 | 2026-05-17 | A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function ogs_sbi_client_add in the library /lib/sbi/client.c of the component NRF. The manipulation o… |
| CVE-2026-8730 | MEDIUM | Patched | 4.3 | 2026-05-17 | A flaw has been found in Open5GS up to 2.7.6. This impacts the function ogs_sbi_nf_instance_set_id in the library /lib/sbi/context.c of the component NRF. Executing a manip… |
| CVE-2026-8729 | MEDIUM | Patched | 4.3 | 2026-05-17 | A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of t… |
| CVE-2026-8728 | MEDIUM | Patched | 4.3 | 2026-05-17 | A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/con… |
| CVE-2026-8724 | MEDIUM | 4.7 | 2026-05-17 | A security flaw has been discovered in Dataease 2.10.20. Impacted is the function SqlparserUtils.transFilter of the file SqlparserUtils.java of the component Data Dashboard… | |
| CVE-2026-8723 | MEDIUM | Patched | 5.3 | 2026-05-17 | ### Summary `qs.stringify` throws `TypeError` when called with `arrayFormat: 'comma'` and `encodeValuesOnly: true` on an array containing `null` or `undefined`. The thro… |
| CVE-2026-8722 | MEDIUM | Patched | 6.5 | 2026-06-04 | Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from … |
| CVE-2026-8716 | MEDIUM | Patched | 4.3 | 2026-05-27 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions c… |
| CVE-2026-8714 | MEDIUM | Patched | 6.5 | 2026-06-05 | A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input. Crafted inputs can… |
| CVE-2026-8708 | MEDIUM | 4.3 | 2026-05-27 | The Genzel breadcrumbs plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2. This is due to missing or incorrect nonce… | |
| CVE-2026-8707 | MEDIUM | 6.1 | 2026-05-27 | The NS Product icon badge plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF in all versions up to, and including, 1.2.4 due to insufficient … | |
| CVE-2026-8706 | MEDIUM | Patched | 6.5 | 2026-05-19 | Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the respons… |
| CVE-2026-8704 | MEDIUM | 6.5 | 2026-05-15 | Crypt::DSA versions through 1.19 for Perl use 2-args open, allowing existing files to be modified. | |
| CVE-2026-8703 | MEDIUM | 6.4 | 2026-05-27 | The Endless Scroll plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Shortcode Attributes in all versions up to, and including, 1.0.0 due to insufficien… | |
| CVE-2026-8702 | MEDIUM | 6.4 | 2026-05-27 | The GBI To Print plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the 'div' attribute of the 'gbitoprint' shortcode. This is due to insu… | |
| CVE-2026-8701 | MEDIUM | 6.4 | 2026-05-27 | The GNTT Post Title Ticker plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0 via the `title-ticker-slide`, `title-ticker-fade`, and `title-ti… | |
| CVE-2026-8698 | MEDIUM | 6.4 | 2026-05-27 | The Cryptocurrency Prijsvergelijking Widget plugin for WordPress is vulnerable to Stored Cross-Site Scripting in version 1.0. This is due to insufficient output escaping in… | |
| CVE-2026-8694 | MEDIUM | Patched | 5.3 | 2026-06-12 | Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defin… |
| CVE-2026-8692 | MEDIUM | 4.3 | 2026-05-22 | The Vedrixa Forms – User Registration Form, Signup Form & Drag & Drop Form Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and inc… | |
| CVE-2026-8690 | MEDIUM | 5.3 | 2026-06-24 | The RentMy Real-Time Rental Management Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.0.4.1. This is due to the p… | |
| CVE-2026-8689 | MEDIUM | 4.3 | 2026-05-28 | The Visualizer: Tables and Charts Manager for WordPress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 3.11.14. This is d… |