Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 451–475 of 163,528 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-84769 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Insecure Direct Object References (IDOR) in Business Directory <= 6.4.26 versions. | |
| CVE-2026-84774 | MEDIUM | 6.1 | 2026-09-03 | Unauthenticated Cross Site Scripting (XSS) in WP Statistics <= 14.16.11 versions. | |
| CVE-2026-84762 | MEDIUM | 5.3 | 2026-09-03 | Unauthenticated Bypass Vulnerability in WP EasyPay <= 4.5.3 versions. | |
| CVE-2026-84766 | MEDIUM | 5.9 | 2026-09-03 | Unauthenticated Bypass Vulnerability in FluentBooking Pro <= 2.2.1 versions. | |
| CVE-2026-84767 | MEDIUM | 5.3 | 2026-09-03 | Unauthenticated Bypass Vulnerability in BookIt <= 2.6.0.3 versions. | |
| CVE-2026-84758 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in Business Directory <= 6.4.26 versions. | |
| CVE-2026-84215 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in Timetics <= 1.0.61 versions. | |
| CVE-2026-84754 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in WPFunnels <= 3.12.13 versions. | |
| CVE-2026-84755 | MEDIUM | 6.5 | 2026-09-03 | Unauthenticated Broken Access Control in Mail Mint <= 1.31.0 versions. | |
| CVE-2026-81282 | MEDIUM | 6.5 | 2026-09-03 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | |
| CVE-2026-75602 | MEDIUM | Patched | 6.5 | 2026-09-03 | OpenList a file list program that supports multiple storage. Prior to 4.2.3, OpenList's offline-download feature at POST /api/fs/add_offline_download with tool: "SimpleHttp… |
| CVE-2026-81281 | MEDIUM | 6.5 | 2026-09-03 | Subscriber Cross Site Scripting (XSS) in Graphene <= 2.9.4 versions. | |
| CVE-2026-84963 | MEDIUM | 5.3 | 2026-09-03 | An incorrect numeric conversion in the JSON parsing component of the MongoDB C Driver's BSON library may cause an unusually large text value to be silently shortened, or th… | |
| CVE-2026-84964 | MEDIUM | 5.9 | 2026-09-03 | A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During … | |
| CVE-2026-84965 | MEDIUM | 5.1 | 2026-09-03 | An integer wraparound in an allocation size calculation in the BSON library's JSON parsing code can cause a buffer to be released while a following copy operation still wri… | |
| CVE-2026-84966 | MEDIUM | 5.1 | 2026-09-03 | An incorrect numeric type conversion in the BSON document building component of the MongoDB C++ Driver may cause a length value to be interpreted incorrectly. When an appli… | |
| CVE-2026-84967 | MEDIUM | 4.3 | 2026-09-03 | A component of the MongoDB extension for Visual Studio Code does not neutralize special characters in a connection string before that value is placed into a command line th… | |
| CVE-2026-84962 | MEDIUM | 4.2 | 2026-09-03 | An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's iden… | |
| CVE-2026-82525 | MEDIUM | Patched | 5.5 | 2026-09-03 | Exterro FTK Imager before 8.3 contains an XML external entity (XXE) injection vulnerability that allows attackers to read arbitrary files from the host filesystem by embedd… |
| CVE-2026-50554 | MEDIUM | Patched | 5.3 | 2026-09-03 | Note Mark is an open-source note-taking application. Prior to version 0.19.5, GET /api/books/{bookID}/notes is an unauthenticated endpoint that accepts a "deleted" query pa… |
| CVE-2026-85210 | MEDIUM | 4.3 | 2026-09-03 | Oppia's AdminRoleHandler GET endpoint in core/controllers/admin.py is decorated with open_access, allowing any registered user to enumerate privileged accounts and roles. A… | |
| CVE-2026-85177 | MEDIUM | 5.4 | 2026-09-03 | CRMEB through 6.0.0 fails to validate message ownership in the edit_message handler of MessageSystemController.php, allowing authenticated users to modify arbitrary system … | |
| CVE-2026-85135 | MEDIUM | 6.3 | 2026-09-03 | A security flaw has been discovered in ILIAS up to 9.21/10.9/11.2. This affects the function ilObjMediaObjectGUI::uploadMultipleSubtitleFileObject of the file Services/Repo… | |
| CVE-2026-84970 | MEDIUM | 6.2 | 2026-09-03 | A numeric truncation weakness exists in the JSON parsing component of the MongoDB C++ Driver's BSON library. An actor who controls the text that an embedding application ha… | |
| CVE-2026-84971 | MEDIUM | 6.5 | 2026-09-03 | Improper handling of an unexpected value size in the decryption path of a client-side encryption library can cause a failed internal check that terminates the process using… |