Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 163,528 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-71429 | MEDIUM | Patched | 6.2 | 2026-09-03 | stream-json is a micro-library of stream components for processing JSON and JSONC with a minimal memory footprint. Prior to 3.5.0, the path filters pick, ignore, filter, an… |
| CVE-2026-85044 | MEDIUM | 6.5 | 2026-09-03 | Use of released resource in Mobile in Google Chrome on on Android prior to 152.0.7977.82 allowed a remote attacker leveraging social engineering to bypass web origin policy… | |
| CVE-2026-19795 | MEDIUM | 6.2 | 2026-09-03 | Qiskit could allow a local attacker to cause a denial of service due to a stack overflow during deserialization of QPY payloads. A malicious QPY payload can trigger a segme… | |
| CVE-2026-85205 | MEDIUM | 6.3 | 2026-09-03 | A vulnerability was determined in itsourcecode Online Medicine Delivery System 1.0. This issue affects the function addwishlist of the file /customer/controller.php?action=… | |
| CVE-2026-85389 | MEDIUM | Patched | 6.5 | 2026-09-03 | Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task … |
| CVE-2026-85392 | MEDIUM | 4.3 | 2026-09-03 | Peppermint through 0.5.5 contains an authorization bypass vulnerability in the GET /api/v1/auth/user/:id/logout endpoint that allows authenticated attackers to delete sessi… | |
| CVE-2026-82298 | MEDIUM | 4.3 | 2026-09-03 | Incorrect Authorization (CWE-863) in Kibana can lead to denial of service via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-82299 | MEDIUM | 6.5 | 2026-09-03 | Incorrect Authorization (CWE-863) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). | |
| CVE-2026-49455 | MEDIUM | Patched | 6.5 | 2026-09-03 | Waku is the minimal React framework. Prior to version 1.0.0-beta.1, Waku's RSC request dispatcher invokes server actions without validating the request's Origin (or Sec-Fet… |
| CVE-2026-78593 | MEDIUM | 4.3 | 2026-09-03 | An insufficiently validated configuration field in Kibana's Cribl integration allows an authenticated user holding Kibana Fleet management privileges to inject attacker-con… | |
| CVE-2026-78595 | MEDIUM | 4.3 | 2026-09-03 | Missing Authorization in Kibana Leading to Information Disclosure / Missing Authorization (CWE-862) in the Kibana Fleet feature can lead to information disclosure via Privi… | |
| CVE-2026-78596 | MEDIUM | 4.3 | 2026-09-03 | Missing Authorization in Kibana Leading to Unauthorized Modification of Data / Missing Authorization (CWE-862) in Kibana can lead to unauthorized modification of data via P… | |
| CVE-2026-84968 | MEDIUM | 5.3 | 2026-09-03 | An out-of-bounds read in the BSON decoding component of the MongoDB PHP driver may allow an unauthenticated party who supplies specially formed input to have a small amount… | |
| CVE-2026-82023 | MEDIUM | Patched | 4.3 | 2026-09-03 | LearnPress WordPress Plugin before 4.4.6 contains a broken object-level authorization vulnerability that allows authenticated attackers with the Instructor role to add answ… |
| CVE-2026-82024 | MEDIUM | Patched | 5.4 | 2026-09-03 | LearnPress WordPress Plugin before 4.4.6 contains a stored cross-site scripting vulnerability that allows authenticated attackers with the Instructor role to inject persist… |
| CVE-2026-85308 | MEDIUM | 5.3 | 2026-09-03 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This … | |
| CVE-2026-85309 | MEDIUM | 5.3 | 2026-09-03 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ult… | |
| CVE-2026-85186 | MEDIUM | 6.3 | 2026-09-03 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/contr… | |
| CVE-2026-85302 | MEDIUM | 6.5 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based … | |
| CVE-2026-85303 | MEDIUM | 6.5 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This is… | |
| CVE-2026-85304 | MEDIUM | 5.3 | 2026-09-03 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access… | |
| CVE-2026-85305 | MEDIUM | 5.4 | 2026-09-03 | Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1. | |
| CVE-2026-85306 | MEDIUM | 6.5 | 2026-09-03 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels… | |
| CVE-2026-85307 | MEDIUM | Patched | 5.3 | 2026-09-03 | Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: … |
| CVE-2026-84849 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. |