Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8688 MEDIUM 4.3 2026-06-24 The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve…
CVE-2026-8685 MEDIUM 6.5 2026-05-20 The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due …
CVE-2026-8684 MEDIUM 5.3 2026-05-22 The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly v…
CVE-2026-8683 MEDIUM Patched 6.5 2026-06-15 Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owne&hellip;
CVE-2026-8682 MEDIUM 4.3 2026-05-28 The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1.&hellip;
CVE-2026-8681 MEDIUM 5.3 2026-05-16 The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly ve&hellip;
CVE-2026-8678 MEDIUM 4.3 2026-07-11 The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that &hellip;
CVE-2026-8677 MEDIUM 6.4 2026-06-09 The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings i&hellip;
CVE-2026-8673 MEDIUM Patched 5.9 2026-05-22 Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0.
CVE-2026-8672 MEDIUM Patched 5.1 2026-05-22 Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: be&hellip;
CVE-2026-86714 MEDIUM 5.4 2026-09-08 PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply&hellip;
CVE-2026-8669 MEDIUM 6.5 2026-05-15 Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single &hellip;
CVE-2026-8667 MEDIUM Patched 4.3 2026-08-12 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou&hellip;
CVE-2026-8664 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host para&hellip;
CVE-2026-8663 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name p&hellip;
CVE-2026-8661 MEDIUM Patched 4.8 2026-06-26 Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbit&hellip;
CVE-2026-86597 MEDIUM 6.5 2026-09-08 Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti&hellip;
CVE-2026-8659 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_p&hellip;
CVE-2026-8658 MEDIUM Patched 6.0 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filte&hellip;
CVE-2026-8656 MEDIUM Patched 6.1 2026-05-16 Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and &hellip;
CVE-2026-86550 MEDIUM 6.5 2026-09-08 NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul&hellip;
CVE-2026-8653 MEDIUM 6.5 2026-06-04 The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to ins&hellip;
CVE-2026-86519 MEDIUM 5.3 2026-09-08 A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handle&hellip;
CVE-2026-86518 MEDIUM 6.3 2026-09-08 A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID lead&hellip;
CVE-2026-86517 MEDIUM 6.3 2026-09-08 A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a man&hellip;