Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 26–50 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-82744 | NONE | Patched | — | 2026-09-01 | Not Failing Securely (Failing Open) vulnerability in ash-project ash skips an Ash.Reactor change when the guard controlling it raises, so a change meant to run does not. A… |
| CVE-2026-82745 | NONE | Patched | — | 2026-09-01 | Improper Access Control vulnerability in ash-project ash lets a create action overwrite an existing record when the ETS or Mnesia data layer is used, because neither enforc… |
| CVE-2026-82746 | NONE | Patched | — | 2026-09-01 | Missing Authorization vulnerability in ash-project ash allows an actor to update records forbidden by resource policies through the atomic path of Ash.update_many/4. Ash.u… |
| CVE-2026-82748 | NONE | Patched | — | 2026-09-01 | Incorrect Authorization vulnerability in ash-project ash authorizes an aggregate under one read action while computing it under another, so an aggregate can run with polici… |
| CVE-2026-82749 | NONE | Patched | — | 2026-09-01 | Incorrect Authorization vulnerability in ash-project ash widens a relationship's parent(...) scoping filter to match unintended records when the referenced parent field can… |
| CVE-2026-12747 | MEDIUM | 6.4 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.… | |
| CVE-2026-13203 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_mod… | |
| CVE-2026-16787 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to… | |
| CVE-2026-17589 | MEDIUM | 4.9 | 2026-09-01 | The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.… | |
| CVE-2026-18752 | MEDIUM | 6.5 | 2026-09-01 | The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient… | |
| CVE-2026-19573 | HIGH | 7.2 | 2026-09-01 | The Affiliate Super Assistent plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘doCommentShortcode’ function in all versions up to, and including, … | |
| CVE-2026-19796 | HIGH | 7.2 | 2026-09-01 | The Listdom: AI-powered Business Directory with Classifieds Ads Listings plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'lsd[displ][style]' Parameter… | |
| CVE-2026-19806 | HIGH | 8.8 | 2026-09-01 | The Support Genix – Helpdesk, AI Chatbot, Knowledge Base & Customer Support Ticketing System plugin for WordPress is vulnerable to Authentication Bypass leading to Administ… | |
| CVE-2026-19948 | MEDIUM | 5.3 | 2026-09-01 | The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versio… | |
| CVE-2026-19952 | HIGH | 7.5 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the move_folders function in all … | |
| CVE-2026-75921 | HIGH | 7.2 | 2026-09-01 | The Master Addons for Elementor – Elementor Addons, Widgets, Mega Menu Builder, Popup Builder, Widget Builder & Template Kits plugin for WordPress is vulnerable to Arbitrar… | |
| CVE-2026-75965 | MEDIUM | 6.4 | 2026-09-01 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' … | |
| CVE-2026-76006 | MEDIUM | 4.9 | 2026-09-01 | The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, … | |
| CVE-2026-77823 | MEDIUM | 4.9 | 2026-09-01 | The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. … | |
| CVE-2026-82747 | NONE | Patched | — | 2026-09-01 | Incorrect Authorization vulnerability in ash-project ash returns records that a runtime read policy denies to any actor. When a resource has an access_type :runtime read p… |
| CVE-2026-83743 | MEDIUM | 6.3 | 2026-09-01 | A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile … | |
| CVE-2026-83744 | MEDIUM | 4.3 | 2026-09-01 | A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/… | |
| CVE-2026-18488 | MEDIUM | 6.4 | 2026-09-01 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and incl… | |
| CVE-2026-75964 | MEDIUM | 6.1 | 2026-09-01 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'em… | |
| CVE-2026-75980 | MEDIUM | 6.4 | 2026-09-01 | The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribut… |