Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,126 CVEs

CVEs (30,126, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 451–475 of 30,126 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86190 CRITICAL 9.1 2026-09-05 WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and li…
CVE-2026-86189 CRITICAL 9.8 2026-09-05 WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a cal…
CVE-2026-86188 HIGH 7.2 2026-09-05 AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browse…
CVE-2026-86187 MEDIUM 5.9 2026-09-05 WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to pass…
CVE-2026-86186 MEDIUM 6.5 2026-09-05 AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force p…
CVE-2026-86185 HIGH 8.0 2026-09-05 Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attack…
CVE-2026-86184 CRITICAL Patched 9.8 2026-09-05 Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user …
CVE-2026-15550 MEDIUM 4.3 2026-09-05 The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability …
CVE-2026-12843 MEDIUM 5.4 2026-09-05 The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is aut…
CVE-2026-10196 CRITICAL Patched 9.8 2026-09-05 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc…
CVE-2025-9049 HIGH 8.8 2026-09-05 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_…
CVE-2025-15647 MEDIUM Patched 5.5 2026-09-05 CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round…
CVE-2025-15614 LOW Patched 3.3 2026-09-05 ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files …
CVE-2026-86178 MEDIUM 5.4 2026-09-05 Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only storie…
CVE-2026-86177 HIGH Patched 8.8 2026-09-05 Pterodactyl Panel before 1.14.1 fails to validate action-specific permissions in scheduled task creation, allowing subusers with only schedule.update permission to execute …
CVE-2026-86176 MEDIUM 4.3 2026-09-05 NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users wit…
CVE-2026-86175 MEDIUM 6.5 2026-09-05 NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve…
CVE-2026-86174 MEDIUM 4.3 2026-09-05 Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrar…
CVE-2026-86173 HIGH 7.5 2026-09-05 MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supp…
CVE-2026-86169 HIGH 8.8 2026-09-05 Axolotl through 0.18.0 contains a remote code execution vulnerability in the multipack patch path where trust_remote_code defaults to None instead of False, causing the sec…
CVE-2026-86124 CRITICAL 9.8 2026-09-05 AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. At…
CVE-2026-86123 HIGH 8.7 2026-09-05 SQL Chat contains four unauthenticated API endpoints that accept client-supplied database connection parameters and execute arbitrary SQL queries against attacker-specified…
CVE-2026-86122 MEDIUM 5.0 2026-09-05 Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs…
CVE-2026-86121 CRITICAL Patched 9.8 2026-09-05 Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthe…
CVE-2026-86120 MEDIUM 4.3 2026-09-05 APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission look…