Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

12,997 CVEs

CVEs (12,997, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 26–50 of 12,997 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-84818 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
CVE-2026-84817 HIGH 7.1 2026-09-08 Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
CVE-2026-81806 HIGH 7.2 2026-09-08 Server-Side Request Forgery (SSRF) vulnerability in John Darrel Hide My WP Ghost allows Server Side Request Forgery. This issue affects Hide My WP Ghost: from n/a through 7.0.09.
CVE-2026-81802 MEDIUM 6.5 2026-09-08 Unauthenticated Insecure Direct Object References (IDOR) in WpEvently <= 5.6.0 versions.
CVE-2026-81798 HIGH 7.1 2026-09-08 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Easy Appointments allows DOM-Based XSS. This issue affects Easy Appoi&hellip;
CVE-2026-81792 MEDIUM 6.5 2026-09-08 Unauthenticated Privilege Escalation in Product Catalog Enquiry for WooCommerce by MultiVendorX <= 6.1.4 versions.
CVE-2026-81790 HIGH Patched 7.5 2026-09-08 Missing Authorization vulnerability in Viszt Péter Csomagpontok és szállítási címkék WooCommerce-hez allows Exploiting Incorrectly Configured Access Control Security Levels&hellip;
CVE-2026-81781 HIGH 7.1 2026-09-08 Missing Authorization vulnerability in Unbounce Unbounce Landing Pages unbounce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects&hellip;
CVE-2026-76561 HIGH 7.2 2026-09-08 A flaw was found in Dogtag PKI, as used by FreeIPA's certificate authority component. The certificate profile import functionality does not fully validate uploaded profile &hellip;
CVE-2026-71375 HIGH Patched 7.4 2026-09-08 Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 bef&hellip;
CVE-2026-71374 CRITICAL Patched 9.8 2026-09-08 Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 1&hellip;
CVE-2026-48888 HIGH Patched 7.5 2026-09-08 Allocation of Resources Without Limits or Throttling vulnerability in Automattic WooCommerce allows HTTP DoS. This issue affects WooCommerce: from n/a before 11.1.0.
CVE-2026-86519 MEDIUM 5.3 2026-09-08 A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handle&hellip;
CVE-2026-86518 MEDIUM 6.3 2026-09-08 A vulnerability has been found in code-projects Student Crud Operation 1.0. This affects an unknown function of the file /edit.php. The manipulation of the argument ID lead&hellip;
CVE-2026-86517 MEDIUM 6.3 2026-09-08 A flaw has been found in itsourcecode Sales and Inventory System 1.0. The impacted element is the function mysqli_query of the file /pages/us_searchfrm.php. Executing a man&hellip;
CVE-2026-86516 MEDIUM 4.7 2026-09-08 A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-&hellip;
CVE-2026-86515 MEDIUM 4.3 2026-09-08 A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manip&hellip;
CVE-2026-86514 MEDIUM 6.3 2026-09-08 A weakness has been identified in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation ca&hellip;
CVE-2026-86513 MEDIUM 5.3 2026-09-08 A security flaw has been discovered in java-json-tools jackson-coreutils 2.0. This vulnerability affects the function TreePointer.tokensFromInput of the file src/main/java/&hellip;
CVE-2026-86512 MEDIUM 6.3 2026-09-08 A vulnerability was identified in java-json-tools json-patch up to 1.13. This affects the function CopyOperation.apply/MoveOperation.apply of the file src/main/java/com/git&hellip;
CVE-2026-86511 MEDIUM 5.3 2026-09-08 A vulnerability was found in java-json-tools jackson-coreutils 2.0. Affected by this vulnerability is the function BigDecimal.toPlainString of the file src/main/java/com/gi&hellip;
CVE-2026-75811 NONE &mdash; 2026-09-08 Improper Restriction of Software Interfaces to Hardware Features in ASUS Armoury Crate allows a local user to modify hardware configuration settings and potentially cause h&hellip;
CVE-2026-75810 NONE &mdash; 2026-09-08 Exposed Dangerous Method or Function in ASUS Armoury Crate allow a local user to cause a brief system stall by bypassing driver authentication and sending requests to trigg&hellip;
CVE-2026-75809 NONE &mdash; 2026-09-08 Exposed IOCTL with insufficient access control in ASUS Armoury Crate allows a local user to disclosure information and disabling device functionality by bypassing driver au&hellip;
CVE-2026-75808 NONE &mdash; 2026-09-08 Allocation of Resources Without Limits or Throttling in ASUS Armoury Crate allows a local user to cause a denial-of-service condition through system memory exhaustion by by&hellip;