Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84769 MEDIUM 6.5 2026-09-03 Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions.
CVE-2026-84774 MEDIUM 6.1 2026-09-03 Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions.
CVE-2026-84762 MEDIUM 5.3 2026-09-03 Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions.
CVE-2026-84766 MEDIUM 5.9 2026-09-03 Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions.
CVE-2026-84767 MEDIUM 5.3 2026-09-03 Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions.
CVE-2026-84758 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions.
CVE-2026-84215 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions.
CVE-2026-84754 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions.
CVE-2026-84755 MEDIUM 6.5 2026-09-03 Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions.
CVE-2026-81282 MEDIUM 6.5 2026-09-03 Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions.
CVE-2026-75602 MEDIUM Patched 6.5 2026-09-03 OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp&hellip;
CVE-2026-81281 MEDIUM 6.5 2026-09-03 Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions.
CVE-2026-84963 MEDIUM 5.3 2026-09-03 An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or th&hellip;
CVE-2026-84964 MEDIUM 5.9 2026-09-03 A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During &hellip;
CVE-2026-84965 MEDIUM 5.1 2026-09-03 An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still wri&hellip;
CVE-2026-84966 MEDIUM 5.1 2026-09-03 An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an appli&hellip;
CVE-2026-84967 MEDIUM 4.3 2026-09-03 A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line th&hellip;
CVE-2026-84962 MEDIUM 4.2 2026-09-03 An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's iden&hellip;
CVE-2026-82525 MEDIUM Patched 5.5 2026-09-03 Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedd&hellip;
CVE-2026-50554 MEDIUM Patched 5.3 2026-09-03 Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query pa&hellip;
CVE-2026-85210 MEDIUM 4.3 2026-09-03 Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. A&hellip;
CVE-2026-85177 MEDIUM 5.4 2026-09-03 CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system &hellip;
CVE-2026-85135 MEDIUM 6.3 2026-09-03 A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repo&hellip;
CVE-2026-84970 MEDIUM 6.2 2026-09-03 A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application ha&hellip;
CVE-2026-84971 MEDIUM 6.5 2026-09-03 Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using&hellip;