Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-71429 MEDIUM Patched 6.2 2026-09-03 stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, an…
CVE-2026-85044 MEDIUM 6.5 2026-09-03 Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy…
CVE-2026-19795 MEDIUM 6.2 2026-09-03 Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segme…
CVE-2026-85205 MEDIUM 6.3 2026-09-03 A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=…
CVE-2026-85389 MEDIUM Patched 6.5 2026-09-03 Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task …
CVE-2026-85392 MEDIUM 4.3 2026-09-03 Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessi…
CVE-2026-82298 MEDIUM 4.3 2026-09-03 Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-82299 MEDIUM 6.5 2026-09-03 Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180).
CVE-2026-49455 MEDIUM Patched 6.5 2026-09-03 Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fet…
CVE-2026-78593 MEDIUM 4.3 2026-09-03 An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-con…
CVE-2026-78595 MEDIUM 4.3 2026-09-03 Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privi…
CVE-2026-78596 MEDIUM 4.3 2026-09-03 Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via P…
CVE-2026-84968 MEDIUM 5.3 2026-09-03 An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount…
CVE-2026-82023 MEDIUM Patched 4.3 2026-09-03 LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answ…
CVE-2026-82024 MEDIUM Patched 5.4 2026-09-03 LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persist…
CVE-2026-85308 MEDIUM 5.3 2026-09-03 Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This …
CVE-2026-85309 MEDIUM 5.3 2026-09-03 Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ult…
CVE-2026-85186 MEDIUM 6.3 2026-09-03 A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/contr…
CVE-2026-85302 MEDIUM 6.5 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based …
CVE-2026-85303 MEDIUM 6.5 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This is…
CVE-2026-85304 MEDIUM 5.3 2026-09-03 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access…
CVE-2026-85305 MEDIUM 5.4 2026-09-03 Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
CVE-2026-85306 MEDIUM 6.5 2026-09-03 Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels…
CVE-2026-85307 MEDIUM Patched 5.3 2026-09-03 Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: …
CVE-2026-84849 MEDIUM 6.5 2026-09-03 Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.