Search
78,484 CVEs
CVEs (78,484, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 78,484 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-10041 | NONE | — | 2026-01-15 | Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An una… | |
| CVE-2011-10043 | CRITICAL | Patched | 9.8 | 2026-07-07 | Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to sp… |
| CVE-2011-20001 | HIGH | 7.5 | 2025-10-14 | A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) … | |
| CVE-2011-20002 | HIGH | 7.4 | 2025-10-14 | A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) … | |
| CVE-2012-10063 | CRITICAL | Patched | 9.8 | 2025-10-30 | Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQ… |
| CVE-2012-10064 | NONE | — | 2026-01-16 | Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secu… | |
| CVE-2013-10031 | HIGH | Patched | 7.5 | 2025-12-09 | Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks |
| CVE-2013-10041 | NONE | — | 2026-04-22 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. | |
| CVE-2013-10045 | NONE | — | 2026-04-22 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. | |
| CVE-2013-10056 | NONE | — | 2026-04-22 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. | |
| CVE-2013-10071 | MEDIUM | Patched | 6.1 | 2025-10-30 | Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation … |
| CVE-2013-10072 | MEDIUM | Patched | 6.5 | 2025-10-30 | Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpo… |
| CVE-2013-10073 | HIGH | Patched | 8.8 | 2025-10-30 | Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate… |
| CVE-2013-10074 | MEDIUM | Patched | 5.4 | 2025-10-30 | Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-suppl… |
| CVE-2013-10075 | CRITICAL | Patched | 9.1 | 2026-05-08 | Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create… |
| CVE-2013-20005 | MEDIUM | 5.3 | 2026-03-16 | Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malic… | |
| CVE-2013-20006 | HIGH | 7.5 | 2026-03-16 | Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being s… | |
| CVE-2014-125112 | CRITICAL | Patched | 9.8 | 2026-03-26 | Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vul… |
| CVE-2014-125120 | NONE | — | 2026-04-22 | Rejected reason: This CVE has the been REJECTED and will not be published by the CNA. | |
| CVE-2014-125128 | MEDIUM | Patched | 6.1 | 2025-09-08 | 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribu… |
| CVE-2015-10145 | HIGH | Patched | 8.8 | 2025-12-31 | Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly… |
| CVE-2015-10146 | MEDIUM | Patched | 4.9 | 2025-10-29 | The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficien… |
| CVE-2015-10147 | MEDIUM | Patched | 4.9 | 2025-10-29 | The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.2 due to insuffici… |
| CVE-2015-10148 | HIGH | 8.2 | 2026-04-03 | Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, al… | |
| CVE-2015-20113 | MEDIUM | 5.3 | 2026-03-16 | Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrativ… |