Search
163,207 CVEs · Medium severity
EOL hidden · Show all products
CVEs (163,207, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 426–450 of 163,207 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-85306 | MEDIUM | 6.5 | 2026-09-03 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels… | |
| CVE-2026-85305 | MEDIUM | 5.4 | 2026-09-03 | Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1. | |
| CVE-2026-85304 | MEDIUM | 5.3 | 2026-09-03 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access… | |
| CVE-2026-85303 | MEDIUM | 6.5 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This is… | |
| CVE-2026-85302 | MEDIUM | 6.5 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based … | |
| CVE-2026-85186 | MEDIUM | 6.3 | 2026-09-03 | A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/contr… | |
| CVE-2026-84849 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions. | |
| CVE-2026-84774 | MEDIUM | 6.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. | |
| CVE-2026-84769 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | |
| CVE-2026-84767 | MEDIUM | 5.3 | 2026-09-03 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | |
| CVE-2026-84766 | MEDIUM | 5.9 | 2026-09-03 | Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | |
| CVE-2026-84762 | MEDIUM | 5.3 | 2026-09-03 | Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | |
| CVE-2026-84758 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | |
| CVE-2026-84755 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | |
| CVE-2026-84754 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | |
| CVE-2026-84215 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | |
| CVE-2026-81282 | MEDIUM | 6.5 | 2026-09-03 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | |
| CVE-2026-81281 | MEDIUM | 6.5 | 2026-09-03 | Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | |
| CVE-2026-75602 | MEDIUM | Patched | 6.5 | 2026-09-03 | OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp… |
| CVE-2026-84967 | MEDIUM | 4.3 | 2026-09-03 | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line th… | |
| CVE-2026-84966 | MEDIUM | 5.1 | 2026-09-03 | An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an appli… | |
| CVE-2026-84965 | MEDIUM | 5.1 | 2026-09-03 | An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still wri… | |
| CVE-2026-84964 | MEDIUM | 5.9 | 2026-09-03 | A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During … | |
| CVE-2026-84963 | MEDIUM | 5.3 | 2026-09-03 | An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or th… | |
| CVE-2026-84962 | MEDIUM | 4.2 | 2026-09-03 | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's iden… |