Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 2,372 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84802 | MEDIUM | Patched | 4.3 | 2026-09-02 | Craft CMS versions from 5.7.0 before 5.10.12 contain an information disclosure vulnerability in AssetsController::actionMoveInfo that fails to enforce volume permissions. A… |
| CVE-2026-84805 | MEDIUM | Patched | 4.3 | 2026-09-02 | Kimai versions from 2.61.0 before 2.63.0 fail to disable admin-only work-contract preferences for low-privilege users in the PATCH /api/users/{id}/preferences endpoint. Alt… |
| CVE-2026-84808 | MEDIUM | Patched | 4.3 | 2026-09-02 | Kimai versions before 2.65.0 contain an authorization bypass vulnerability in the REST API timesheet collection endpoint that fails to enforce activity-team access controls… |
| CVE-2026-84799 | MEDIUM | Patched | 4.3 | 2026-09-02 | Craft CMS before 5.11.0 fails to enforce user-group scope filters on native GraphQL user relations including author, authors, uploader, draftCreator, and revisionCreator fi… |
| CVE-2026-84792 | MEDIUM | Patched | 4.3 | 2026-09-02 | Craft CMS versions before 5.10.11 contain a broken access control vulnerability in the element-indexes/save-elements endpoint that allows control panel users to move entrie… |
| CVE-2026-53683 | MEDIUM | 4.3 | 2026-09-02 | reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by … | |
| CVE-2026-81426 | MEDIUM | Patched | 4.3 | 2026-09-02 | The WC Vendors WordPress plugin before 2.7.2.1 does not have CSRF protection on some of its front-end order shipment status actions, which could allow attackers to make a … |
| CVE-2026-81427 | MEDIUM | Patched | 4.3 | 2026-09-02 | The WC Vendors WordPress plugin before 2.7.2.1 does not verify that the vendor submitting a front-end order shipment status change owns the referenced order, allowing any … |
| CVE-2026-81432 | MEDIUM | Patched | 4.3 | 2026-09-02 | The JetStyleManager for Gutenberg WordPress plugin before 1.3.9 does not have CSRF protection on some of its AJAX actions, allowing attackers to make a logged-in user with … |
| CVE-2026-79621 | MEDIUM | Patched | 4.3 | 2026-09-02 | The CatalogX WordPress plugin before 6.1.3 does not sanitise or escape content that an unauthenticated user can store before including it in the product enquiry notificati… |
| CVE-2026-81194 | MEDIUM | Patched | 4.3 | 2026-09-02 | The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.46 does not properly verify authorization when retrieving order line-item data, allowing any authenticated… |
| CVE-2026-77764 | MEDIUM | Patched | 4.3 | 2026-09-02 | The GamiPress WordPress plugin before 7.9.9.6 does not properly restrict its video watch-tracking functionality, allowing users with a role as low as Subscriber to award t… |
| CVE-2026-16983 | MEDIUM | Patched | 4.3 | 2026-09-02 | The Gutentor WordPress plugin before 4.0.6 does not apply the correct context restriction to one of its REST endpoints, exposing the plaintext passwords of password-protec… |
| CVE-2026-84425 | MEDIUM | 4.3 | 2026-09-02 | A vulnerability was found in zhayujie CowAgent up to 2.1.3. This impacts the function BrowserTool of the file agent/tools/browser/browser_tool.py of the component Browser T… | |
| CVE-2026-84427 | MEDIUM | 4.3 | 2026-09-02 | A vulnerability was determined in zhayujie CowAgent up to 2.1.7. Affected is an unknown function of the file agent/tools/bash/bash.py of the component Bash Tool. Executing … | |
| CVE-2026-84356 | MEDIUM | Patched | 4.3 | 2026-09-02 | UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low) |
| CVE-2026-84288 | MEDIUM | 4.3 | 2026-09-01 | A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the componen… | |
| CVE-2026-84289 | MEDIUM | 4.3 | 2026-09-01 | A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP T… | |
| CVE-2026-84287 | MEDIUM | 4.3 | 2026-09-01 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is some unknown functionality of the file gateway/platforms/api_server.py of the component… | |
| CVE-2026-78597 | MEDIUM | Patched | 4.3 | 2026-09-01 | Missing Authorization (CWE-862) in the Kibana Entity Store feature can lead to unauthorized credential creation via Accessing Functionality Not Properly Constrained by ACLs… |
| CVE-2026-78603 | MEDIUM | Patched | 4.3 | 2026-09-01 | Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Exploiting Incorrectly Configured Access Control Security Levels (CAPEC-180). An authentica… |
| CVE-2026-73741 | MEDIUM | Patched | 4.3 | 2026-09-01 | A vulnerability in the API of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to view some system files. Successful exploitation cou… |
| CVE-2026-73742 | MEDIUM | Patched | 4.3 | 2026-09-01 | A vulnerability in an API endpoint of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to spoof the source address attributed to thei… |
| CVE-2026-72633 | MEDIUM | Patched | 4.3 | 2026-09-01 | Incorrect Authorization (CWE-863) in Kibana Entity Analytics can lead to a loss of security monitoring via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1… |
| CVE-2026-84267 | MEDIUM | 4.3 | 2026-09-01 | A flaw was found in the SFTP backend in gvfs. When mounting a share, a malicious SFTP server can cause read_string() to allocate a buffer with a certain length but the func… |