Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 163,528 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8688 | MEDIUM | 4.3 | 2026-06-24 | The Advance Nav Menu Manager plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.3. This is due to the plugin not properly ve… | |
| CVE-2026-8685 | MEDIUM | 6.5 | 2026-05-20 | The Infility Global plugin for WordPress is vulnerable to SQL Injection via the 'orderby' and 'order' parameters in all versions up to, and including, 2.15.16. This is due … | |
| CVE-2026-8684 | MEDIUM | 5.3 | 2026-05-22 | The MotoPress Hotel Booking plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.1. This is due to the plugin not properly v… | |
| CVE-2026-8683 | MEDIUM | Patched | 6.5 | 2026-06-15 | Mattermost Desktop App versions <=6.1 5.5.13.0 fail to account for attempting to open extremely long URLs in the Mattermost Desktop App which allows a malicious server owne… |
| CVE-2026-8682 | MEDIUM | 4.3 | 2026-05-28 | The 3D Viewer – 3D Model Viewer – Augmented Reality – Virtual Try On plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.0.1.… | |
| CVE-2026-8681 | MEDIUM | 5.3 | 2026-05-16 | The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly ve… | |
| CVE-2026-8678 | MEDIUM | 4.3 | 2026-07-11 | The MyParcel plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 4.25.1. This is due to the plugin not properly verifying that … | |
| CVE-2026-8677 | MEDIUM | 6.4 | 2026-06-09 | The Prime Elementor Addons – Lightweight Elementor Widgets for Faster Pages plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Widget HTML Tag Settings i… | |
| CVE-2026-8673 | MEDIUM | Patched | 5.9 | 2026-05-22 | Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks. This issue affects Avantra: before 25.3.0. |
| CVE-2026-8672 | MEDIUM | Patched | 5.1 | 2026-05-22 | Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords. This issue affects Avantra: be… |
| CVE-2026-86714 | MEDIUM | 5.4 | 2026-09-08 | PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnerability in the netman system command that fails to validate interface name length. Attackers can supply… | |
| CVE-2026-8669 | MEDIUM | 6.5 | 2026-05-15 | Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single … | |
| CVE-2026-8667 | MEDIUM | Patched | 4.3 | 2026-08-12 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.6 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions cou… |
| CVE-2026-8664 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host para… |
| CVE-2026-8663 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name p… |
| CVE-2026-8661 | MEDIUM | Patched | 4.8 | 2026-06-26 | Server-Side Request Forgery in the markdown_to_pdf action of Rapid7 InsightConnect Markdown Plugin on Linux in versions prior to 4.0.2 allows remote attackers to make arbit… |
| CVE-2026-86597 | MEDIUM | 6.5 | 2026-09-08 | Insertion of sensitive information into log files in the Snowflake Python, Go, JDBC, Node.js, PHP PDO, and ODBC drivers allowed authentication tokens, query-result encrypti… | |
| CVE-2026-8659 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_p… |
| CVE-2026-8658 | MEDIUM | Patched | 6.0 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filte… |
| CVE-2026-8656 | MEDIUM | Patched | 6.1 | 2026-05-16 | Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and … |
| CVE-2026-86550 | MEDIUM | 6.5 | 2026-09-08 | NuBrowser lacks protocol whitelist validation for the S.browser_fallback_url field of intent://, allowing attackers to inject javascript: URLs via 302 redirects. This resul… | |
| CVE-2026-8653 | MEDIUM | 6.5 | 2026-06-04 | The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to ins… | |
| CVE-2026-86519 | MEDIUM | 5.3 | 2026-09-08 | A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handle… | |
| CVE-2026-86518 | MEDIUM | 6.3 | 2026-09-08 | A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID lead… | |
| CVE-2026-86517 | MEDIUM | 6.3 | 2026-09-08 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a man… |