Search
158,556 CVEs · Medium severity
CVEs (158,556, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 158,556 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8627 | MEDIUM | 6.1 | 2026-05-20 | The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is d… | |
| CVE-2026-8626 | MEDIUM | 6.1 | 2026-05-20 | The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient in… | |
| CVE-2026-8624 | MEDIUM | 6.1 | 2026-05-20 | The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 du… | |
| CVE-2026-8622 | MEDIUM | 6.1 | 2026-06-24 | The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to… | |
| CVE-2026-8617 | MEDIUM | 5.3 | 2026-06-24 | The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capabi… | |
| CVE-2026-8616 | MEDIUM | 5.3 | 2026-07-17 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the … | |
| CVE-2026-8614 | MEDIUM | 4.3 | 2026-06-24 | The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin… | |
| CVE-2026-8613 | MEDIUM | 6.4 | 2026-06-10 | The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.… | |
| CVE-2026-8612 | MEDIUM | Patched | 5.3 | 2026-05-15 | WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code executi… |
| CVE-2026-8611 | MEDIUM | 4.3 | 2026-06-06 | The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.4 via the 'invoice_id' par… | |
| CVE-2026-8610 | MEDIUM | 4.3 | 2026-05-20 | The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not pro… | |
| CVE-2026-8609 | MEDIUM | Patched | 5.3 | 2026-07-10 | An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash… |
| CVE-2026-8608 | MEDIUM | 5.3 | 2026-06-06 | The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and i… | |
| CVE-2026-8606 | MEDIUM | Patched | 5.9 | 2026-05-27 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to interna… |
| CVE-2026-8599 | MEDIUM | 6.4 | 2026-06-09 | The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Con… | |
| CVE-2026-8595 | MEDIUM | Patched | 6.8 | 2026-07-10 | A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who vi… |
| CVE-2026-8594 | MEDIUM | 6.2 | 2026-05-30 | Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific … | |
| CVE-2026-8586 | MEDIUM | Patched | 5.5 | 2026-05-14 | Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (C… |
| CVE-2026-8584 | MEDIUM | 4.2 | 2026-05-14 | Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI spoof… | |
| CVE-2026-8583 | MEDIUM | Patched | 5.3 | 2026-05-14 | Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain po… |
| CVE-2026-8582 | MEDIUM | Patched | 5.3 | 2026-05-14 | Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a craf… |
| CVE-2026-8576 | MEDIUM | Patched | 4.3 | 2026-05-14 | Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML p… |
| CVE-2026-8570 | MEDIUM | Patched | 6.5 | 2026-05-14 | Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML p… |
| CVE-2026-8567 | MEDIUM | Patched | 4.3 | 2026-05-14 | Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (C… |
| CVE-2026-8566 | MEDIUM | Patched | 4.3 | 2026-05-14 | Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a craft… |