Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 2,281 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2023-54391 | CRITICAL | Patched | 9.8 | 2026-09-01 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers… |
| CVE-2024-10085 | NONE | — | 2026-09-01 | CWE-770: Allocation of Resources Without Limits or Throttling vulnerability exists that could cause denial of service of the OPC UA communication platform when a large numb… | |
| CVE-2024-11080 | CRITICAL | 9.8 | 2026-09-05 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t… | |
| CVE-2024-14047 | HIGH | 7.2 | 2026-09-01 | A local vulnerability in the Winlogbeat Windows installer caused runtime files to be placed in a directory writable by unprivileged users. A low-privileged attacker with ex… | |
| CVE-2024-35585 | HIGH | Patched | 8.6 | 2026-09-02 | Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication. |
| CVE-2024-3773 | MEDIUM | 5.9 | 2026-09-02 | The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the … | |
| CVE-2024-7952 | NONE | — | 2026-09-01 | A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authenticatio… | |
| CVE-2024-7953 | NONE | — | 2026-09-01 | A vulnerability exists in the affected products that allows a threat actor to create a project and become the administrator for it. If exploited, a threat actor could creat… | |
| CVE-2024-7956 | NONE | — | 2026-09-02 | A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic… | |
| CVE-2025-12737 | HIGH | 8.4 | 2026-09-03 | The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative… | |
| CVE-2025-12768 | NONE | — | 2026-09-01 | A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code exe… | |
| CVE-2025-13398 | NONE | — | 2026-09-02 | Rejected reason: This CVE ID is a duplicate of CVE-2025-13542 and was never published. Both IDs were assigned to the same unauthenticated privilege escalation vulnerability… | |
| CVE-2025-14945 | MEDIUM | 5.4 | 2026-09-05 | The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up … | |
| CVE-2025-15481 | MEDIUM | 5.3 | 2026-09-02 | The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails. | |
| CVE-2025-15485 | HIGH | 8.2 | 2026-09-02 | The Auto x LINE WordPress plugin through 1.0.0 does not have authorization checks in some of its REST endpoints, allowing unauthenticated users to call them and update the … | |
| CVE-2025-15489 | MEDIUM | Patched | 5.3 | 2026-09-02 | The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content |
| CVE-2025-15490 | MEDIUM | Patched | 5.3 | 2026-09-02 | The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs |
| CVE-2025-15613 | MEDIUM | 6.5 | 2026-09-01 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici… | |
| CVE-2025-15614 | LOW | Patched | 3.3 | 2026-09-05 | ugrep before 7.6.0 contains a heap buffer over-read vulnerability in the LZW decompressor when processing crafted .Z archive files. Attackers can supply malformed .Z files … |
| CVE-2025-15647 | MEDIUM | Patched | 5.5 | 2026-09-05 | CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round… |
| CVE-2025-15663 | MEDIUM | Patched | 6.8 | 2026-09-02 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side scri… |
| CVE-2025-15664 | MEDIUM | Patched | 6.8 | 2026-09-02 | The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side scr… |
| CVE-2025-15691 | MEDIUM | Patched | 5.3 | 2026-09-04 | The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying… |
| CVE-2025-15692 | LOW | Patched | 3.5 | 2026-09-02 | The Icegram Express WordPress plugin before 5.8.6 does not properly escape a list description setting before outputting it within an HTML attribute, which could allow users… |