Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

29,735 CVEs · Medium severity

CVEs (29,735, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 426–450 of 29,735 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85306 MEDIUM 6.5 2026-09-03 Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels…
CVE-2026-85305 MEDIUM 5.4 2026-09-03 Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
CVE-2026-85304 MEDIUM 5.3 2026-09-03 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access…
CVE-2026-85303 MEDIUM 6.5 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This is…
CVE-2026-85302 MEDIUM 6.5 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based …
CVE-2026-85186 MEDIUM 6.3 2026-09-03 A weakness has been identified in itsourcecode Online Medicine Delivery System 1.0. Affected by this vulnerability is the function doupdateimage of the file /customer/contr…
CVE-2026-84849 MEDIUM 6.5 2026-09-03 Unauthenticated Bypass Vulnerability in Pre-Orders for WooCommerce <= 2.3 versions.
CVE-2026-84774 MEDIUM 6.1 2026-09-03 Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-84769 MEDIUM 6.5 2026-09-03 Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
CVE-2026-84767 MEDIUM 5.3 2026-09-03 Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
CVE-2026-84766 MEDIUM 5.9 2026-09-03 Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84762 MEDIUM 5.3 2026-09-03 Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
CVE-2026-84758 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84755 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
CVE-2026-84754 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-84215 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
CVE-2026-81282 MEDIUM 6.5 2026-09-03 Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
CVE-2026-81281 MEDIUM 6.5 2026-09-03 Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
CVE-2026-75602 MEDIUM Patched 6.5 2026-09-03 OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp&hellip;
CVE-2026-84967 MEDIUM 4.3 2026-09-03 A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line th&hellip;
CVE-2026-84966 MEDIUM 5.1 2026-09-03 An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an appli&hellip;
CVE-2026-84965 MEDIUM 5.1 2026-09-03 An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still wri&hellip;
CVE-2026-84964 MEDIUM 5.9 2026-09-03 A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During &hellip;
CVE-2026-84963 MEDIUM 5.3 2026-09-03 An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or th&hellip;
CVE-2026-84962 MEDIUM 4.2 2026-09-03 An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's iden&hellip;