Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,281 CVEs

CVEs (2,281, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 2,281 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2023-54356 LOW Patched 3.7 2026-09-01 Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These…
CVE-2023-54391 CRITICAL Patched 9.8 2026-09-01 Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers…
CVE-2024-10085 NONE — 2026-09-01 CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large numb…
CVE-2024-11080 CRITICAL 9.8 2026-09-05 The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t…
CVE-2024-14047 HIGH 7.2 2026-09-01 A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex…
CVE-2024-35585 HIGH Patched 8.6 2026-09-02 Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
CVE-2024-3773 MEDIUM 5.9 2026-09-02 The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …
CVE-2024-7952 NONE — 2026-09-01 A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio…
CVE-2024-7953 NONE — 2026-09-01 A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat…
CVE-2024-7956 NONE — 2026-09-02 A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic…
CVE-2025-12737 HIGH 8.4 2026-09-03 The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative…
CVE-2025-12768 NONE — 2026-09-01 A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe…
CVE-2025-13398 NONE — 2026-09-02 Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability…
CVE-2025-14945 MEDIUM 5.4 2026-09-05 The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up …
CVE-2025-15481 MEDIUM 5.3 2026-09-02 The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
CVE-2025-15485 HIGH 8.2 2026-09-02 The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the …
CVE-2025-15489 MEDIUM Patched 5.3 2026-09-02 The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content
CVE-2025-15490 MEDIUM Patched 5.3 2026-09-02 The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
CVE-2025-15613 MEDIUM 6.5 2026-09-01 Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici…
CVE-2025-15614 LOW Patched 3.3 2026-09-05 ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files …
CVE-2025-15647 MEDIUM Patched 5.5 2026-09-05 CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round…
CVE-2025-15663 MEDIUM Patched 6.8 2026-09-02 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side scri…
CVE-2025-15664 MEDIUM Patched 6.8 2026-09-02 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side scr…
CVE-2025-15691 MEDIUM Patched 5.3 2026-09-04 The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying…
CVE-2025-15692 LOW Patched 3.5 2026-09-02 The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users…