Search
153,531 CVEs · Medium severity
CVEs (153,531, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 153,531 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-8078 | MEDIUM | 4.8 | 2026-06-08 | Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change globa… | |
| CVE-2026-8063 | MEDIUM | Patched | 6.5 | 2026-05-07 | An authenticated user can crash mongod when running $rankFusion or $scoreFusion with an empty pipeline on a view. When resolving a view, the server inspects the aggregatio… |
| CVE-2026-8052 | MEDIUM | Patched | 6.0 | 2026-05-12 | HashiCorp Nomad’s exec2 task driver prior to 0.1.2 is vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. Thi… |
| CVE-2026-8048 | MEDIUM | 6.4 | 2026-05-27 | The My Email Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subject' shortcode attribute in the 'my-email' shortcode in all versions u… | |
| CVE-2026-8042 | MEDIUM | 6.4 | 2026-05-27 | The Github Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'repo' shortcode attribute in the 'github' shortcode in all versions up to, a… | |
| CVE-2026-8040 | MEDIUM | 6.4 | 2026-05-27 | The faq shortocde plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'color' shortcode attribute in the 'faq' shortcode in all versions up to, and in… | |
| CVE-2026-8038 | MEDIUM | 6.4 | 2026-05-20 | The Faces of Users plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'default' shortcode attribute in the 'facesofusers' shortcode in all versions u… | |
| CVE-2026-8033 | MEDIUM | 5.3 | 2026-05-06 | A vulnerability has been found in PicoTronica e-Clinic Healthcare System ECHS 5.7. This affects an unknown function of the file /cdemos/echs/api/v2/ of the component Respon… | |
| CVE-2026-8031 | MEDIUM | 5.3 | 2026-05-06 | A vulnerability was detected in PicoTronica e-Clinic Healthcare System ECHS 5.7. The affected element is an unknown function of the file /cdemos/echs/api/v2/patient-records… | |
| CVE-2026-8027 | MEDIUM | Patched | 4.3 | 2026-05-06 | A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This … |
| CVE-2026-8021 | MEDIUM | Patched | 4.2 | 2026-05-06 | Script injection in UI in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts … |
| CVE-2026-8020 | MEDIUM | Patched | 5.3 | 2026-05-06 | Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to obtain potentially sensiti… |
| CVE-2026-8019 | MEDIUM | Patched | 5.4 | 2026-05-06 | Insufficient policy enforcement in WebApp in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium securi… |
| CVE-2026-8015 | MEDIUM | Patched | 5.4 | 2026-05-06 | Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security s… |
| CVE-2026-8014 | MEDIUM | Patched | 4.3 | 2026-05-06 | Inappropriate implementation in Preload in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium secur… |
| CVE-2026-8013 | MEDIUM | Patched | 4.3 | 2026-05-06 | Insufficient validation of untrusted input in FedCM in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Ch… |
| CVE-2026-8012 | MEDIUM | Patched | 5.4 | 2026-05-06 | Inappropriate implementation in MHTML in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts… |
| CVE-2026-8011 | MEDIUM | Patched | 4.3 | 2026-05-06 | Insufficient policy enforcement in Search in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium sec… |
| CVE-2026-8010 | MEDIUM | Patched | 6.3 | 2026-05-06 | Insufficient validation of untrusted input in SiteIsolation in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to by… |
| CVE-2026-8009 | MEDIUM | Patched | 5.0 | 2026-05-06 | Inappropriate implementation in Cast in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass navigation restric… |
| CVE-2026-8008 | MEDIUM | Patched | 5.4 | 2026-05-06 | Inappropriate implementation in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI spo… |
| CVE-2026-8006 | MEDIUM | Patched | 5.4 | 2026-05-06 | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to perform UI … |
| CVE-2026-8005 | MEDIUM | Patched | 4.3 | 2026-05-06 | Insufficient validation of untrusted input in Cast in Google Chrome prior to 148.0.7778.96 allowed an attacker on the local network segment to bypass same origin policy via… |
| CVE-2026-8004 | MEDIUM | Patched | 4.3 | 2026-05-06 | Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to leak cross-… |
| CVE-2026-8003 | MEDIUM | Patched | 5.4 | 2026-05-06 | Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via malicious network traff… |