Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

78,484 CVEs

CVEs (78,484, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 78,484 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2011-10041 NONE — 2026-01-15 Uploadify WordPress plugin versions up to and including 1.0 contain an arbitrary file upload vulnerability in process_upload.php due to missing file type validation. An una…
CVE-2011-10043 CRITICAL Patched 9.8 2026-07-07 Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to sp…
CVE-2011-20001 HIGH 7.5 2025-10-14 A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) &hellip;
CVE-2011-20002 HIGH 7.4 2025-10-14 A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) &hellip;
CVE-2012-10063 CRITICAL Patched 9.8 2025-10-30 Nagios XI versions prior to 2012R1.3 contain a SQL injection vulnerability in the legacy Core Configuration Manager (CCM) interface. Authenticated users could manipulate SQ&hellip;
CVE-2012-10064 NONE &mdash; 2026-01-16 Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secu&hellip;
CVE-2013-10031 HIGH Patched 7.5 2025-12-09 Plack-Middleware-Session versions before 0.17 may be vulnerable to HMAC comparison timing attacks
CVE-2013-10041 NONE &mdash; 2026-04-22 Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2013-10045 NONE &mdash; 2026-04-22 Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2013-10056 NONE &mdash; 2026-04-22 Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2013-10071 MEDIUM Patched 6.1 2025-10-30 Nagios XI versions prior to 2012R1.6 contain a reflected cross-site scripting (XSS) vulnerability in the dashboard dashlet AJAX load functionality. Insufficient validation &hellip;
CVE-2013-10072 MEDIUM Patched 6.5 2025-10-30 Nagios XI versions prior to 2012R1.6 contain an authorization flaw in the Auto-Discovery functionality. Users with read-only roles could directly reach Auto-Discovery endpo&hellip;
CVE-2013-10073 HIGH Patched 8.8 2025-10-30 Nagios XI versions prior to 2012R1.6 contain a shell command injection vulnerability in the Auto-Discovery tool. User-controlled input is passed to a shell without adequate&hellip;
CVE-2013-10074 MEDIUM Patched 5.4 2025-10-30 Nagios XI versions prior to 2012R2.6 are vulnerable to cross-site scripting (XSS) via the Tools Menu of the web interface. Insufficient validation or escaping of user-suppl&hellip;
CVE-2013-10075 CRITICAL Patched 9.1 2026-05-08 Apache::Session versions through 1.94 for Perl re-creates deleted sessions. The session stores Apache::Session::Store::File and Apache::Session::Store::DB_File will create&hellip;
CVE-2013-20005 MEDIUM 5.3 2026-03-16 Qool CMS 2.0 RC2 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by tricking logged-in users into visiting malic&hellip;
CVE-2013-20006 HIGH 7.5 2026-03-16 Qool CMS contains multiple persistent cross-site scripting vulnerabilities in several administrative scripts where POST parameters are not properly sanitized before being s&hellip;
CVE-2014-125112 CRITICAL Patched 9.8 2026-03-26 Plack::Middleware::Session::Cookie versions through 0.21 for Perl allows remote code execution. Plack::Middleware::Session::Cookie versions through 0.21 has a security vul&hellip;
CVE-2014-125120 NONE &mdash; 2026-04-22 Rejected reason: This CVE has the been REJECTED and will not be published by the CNA.
CVE-2014-125128 MEDIUM Patched 6.1 2025-09-08 'sanitize-html' prior to version 1.0.3 is vulnerable to Cross-site Scripting (XSS). The function 'naughtyHref' doesn't properly validate the hyperreference (`href`) attribu&hellip;
CVE-2015-10145 HIGH Patched 8.8 2025-12-31 Gargoyle router management utility versions 1.5.x contain an authenticated OS command execution vulnerability in /utility/run_commands.sh. The application fails to properly&hellip;
CVE-2015-10146 MEDIUM Patched 4.9 2025-10-29 The Thumbnail Slider With Lightbox plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.4 due to insufficien&hellip;
CVE-2015-10147 MEDIUM Patched 4.9 2025-10-29 The Easy Testimonial Slider and Form plugin for WordPress is vulnerable to SQL Injection via the 'id' parameter in all versions up to, and including, 1.0.2 due to insuffici&hellip;
CVE-2015-10148 HIGH 8.2 2026-04-03 Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior to 8.80 and OpenBAT prior to 9.10 are shipped with identical default SSH and SSL keys that cannot be changed, al&hellip;
CVE-2015-20113 MEDIUM 5.3 2026-03-16 Next Click Ventures RealtyScript 4.0.2 contains cross-site request forgery and persistent cross-site scripting vulnerabilities that allow attackers to perform administrativ&hellip;