Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 9,831 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9773 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected instal… |
| CVE-2026-9772 | HIGH | Patched | 8.8 | 2026-06-24 | Unraid Web Server FileUpload Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected install… |
| CVE-2026-9770 | NONE | — | 2026-07-15 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to th… | |
| CVE-2026-9762 | HIGH | 7.8 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. | |
| CVE-2026-9756 | MEDIUM | 6.4 | 2026-07-03 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an… | |
| CVE-2026-9738 | MEDIUM | 4.4 | 2026-07-11 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and… | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-9734 | MEDIUM | 4.3 | 2026-07-18 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor… | |
| CVE-2026-9731 | MEDIUM | 4.3 | 2026-07-08 | The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce val… | |
| CVE-2026-9729 | MEDIUM | 6.4 | 2026-07-23 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par… | |
| CVE-2026-9726 | CRITICAL | 9.8 | 2026-07-10 | Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This iss… | |
| CVE-2026-9725 | CRITICAL | 9.1 | 2026-07-03 | The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is du… | |
| CVE-2026-9724 | MEDIUM | 4.3 | 2026-06-24 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida… | |
| CVE-2026-9721 | MEDIUM | 4.3 | 2026-06-24 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre… | |
| CVE-2026-9718 | MEDIUM | Patched | 6.5 | 2026-06-25 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s… |
| CVE-2026-9717 | HIGH | Patched | 7.2 | 2026-06-25 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with eleva… |
| CVE-2026-9716 | HIGH | Patched | 7.5 | 2026-06-25 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable… |
| CVE-2026-9713 | HIGH | 7.5 | 2026-07-23 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed… | |
| CVE-2026-9711 | CRITICAL | 9.8 | 2026-06-30 | The EventON - WordPress Virtual Event Calendar Plugin plugin for WordPress (full) is vulnerable to SQL Injection via the WordPress 'search' parameter in versions up to, and… | |
| CVE-2026-9710 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to ever… |
| CVE-2026-9709 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of … |
| CVE-2026-9708 | MEDIUM | Patched | 4.9 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel… |
| CVE-2026-9705 | MEDIUM | Patched | 6.5 | 2026-06-25 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerabil… |
| CVE-2026-9702 | HIGH | Patched | 7.5 | 2026-06-25 | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destin… |
| CVE-2026-9701 | CRITICAL | 9.8 | 2026-07-08 | The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of th… |