Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

158,556 CVEs · Medium severity

CVEs (158,556, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 158,556 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-8627 MEDIUM 6.1 2026-05-20 The Correct Prices plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the $_SERVER['PHP_SELF'] variable in versions up to and including 1.0. This is d…
CVE-2026-8626 MEDIUM 6.1 2026-05-20 The SponsorMe plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.5.2 due to insufficient in…
CVE-2026-8624 MEDIUM 6.1 2026-05-20 The LJ comments import: reloaded plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Parameter in all versions up to, and including, 0.97.1 du…
CVE-2026-8622 MEDIUM 6.1 2026-06-24 The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to…
CVE-2026-8617 MEDIUM 5.3 2026-06-24 The SearchPlus plugin for WordPress is vulnerable to unauthorized modification and deletion of data in versions up to, and including, 1.7.1. This is due to a missing capabi…
CVE-2026-8616 MEDIUM 5.3 2026-07-17 The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the …
CVE-2026-8614 MEDIUM 4.3 2026-06-24 The Assistio plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce verification on the assistio_plugin…
CVE-2026-8613 MEDIUM 6.4 2026-06-10 The aThemes Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'title_tag' Widget Setting in all versions up to, and including, 1.1.…
CVE-2026-8612 MEDIUM Patched 5.3 2026-05-15 WWW::Mechanize::Cached versions before 2.00 for Perl deserialize cached HTTP responses from a world-writable on-disk cache, enabling local response forgery and code executi…
CVE-2026-8611 MEDIUM 4.3 2026-06-06 The Klamra Paycal for Aspaclaria plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.4 via the 'invoice_id' par…
CVE-2026-8610 MEDIUM 4.3 2026-05-20 The TypeSquare Webfonts for ConoHa plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.4. This is due to the plugin not pro…
CVE-2026-8609 MEDIUM Patched 5.3 2026-07-10 An unauthenticated attacker can repeatedly call Grafana's OAuth login route with unique values, causing unbounded memory growth that can eventually exhaust memory and crash…
CVE-2026-8608 MEDIUM 5.3 2026-06-06 The Event Monster – Event Management, Events Calendar, Tickets plugin for WordPress is vulnerable to Insufficient Verification of Data Authenticity in versions up to, and i…
CVE-2026-8606 MEDIUM Patched 5.9 2026-05-27 A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to interna…
CVE-2026-8599 MEDIUM 6.4 2026-06-09 The MailerPress – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Campaign HTML Con…
CVE-2026-8595 MEDIUM Patched 6.8 2026-07-10 A user with Editor permissions can craft a dashboard whose table (TableNG) panel contains a malicious field name that executes as a script in the browser of any user who vi…
CVE-2026-8594 MEDIUM 6.2 2026-05-30 Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters. Text::LineFold splits the input string by specific …
CVE-2026-8586 MEDIUM Patched 5.5 2026-05-14 Inappropriate implementation in Chromoting in Google Chrome prior to 148.0.7778.168 allowed a local attacker to bypass discretionary access control via a malicious file. (C…
CVE-2026-8584 MEDIUM 4.2 2026-05-14 Inappropriate implementation in Views in Google Chrome on iOS prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to perform UI spoof…
CVE-2026-8583 MEDIUM Patched 5.3 2026-05-14 Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to obtain po…
CVE-2026-8582 MEDIUM Patched 5.3 2026-05-14 Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a craf…
CVE-2026-8576 MEDIUM Patched 4.3 2026-05-14 Inappropriate implementation in CORS in Google Chrome on Linux and ChromeOS prior to 148.0.7778.168 allowed a remote attacker to leak cross-origin data via a crafted HTML p…
CVE-2026-8570 MEDIUM Patched 6.5 2026-05-14 Type Confusion in V8 in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML p…
CVE-2026-8567 MEDIUM Patched 4.3 2026-05-14 Integer overflow in ANGLE in Google Chrome on Windows prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (C…
CVE-2026-8566 MEDIUM Patched 4.3 2026-05-14 Insufficient policy enforcement in Payments in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to bypass discretionary access control via a craft…