Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 476–500 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-85390 HIGH 7.1 2026-09-03 Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform admin…
CVE-2026-85389 MEDIUM Patched 6.5 2026-09-03 Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task …
CVE-2026-85388 HIGH 8.1 2026-09-03 Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL…
CVE-2026-85383 MEDIUM 6.3 2026-09-04 A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation o…
CVE-2026-85382 MEDIUM 4.3 2026-09-04 A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d…
CVE-2026-85381 MEDIUM 5.3 2026-09-04 A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unkno…
CVE-2026-85380 HIGH 7.3 2026-09-04 A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function c…
CVE-2026-85379 HIGH 7.3 2026-09-04 A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterMod…
CVE-2026-85378 HIGH 7.3 2026-09-03 A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Au…
CVE-2026-85311 MEDIUM 5.3 2026-09-04 Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: fro…
CVE-2026-85309 MEDIUM 5.3 2026-09-03 Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ult…
CVE-2026-85308 MEDIUM 5.3 2026-09-03 Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This …
CVE-2026-85307 MEDIUM Patched 5.3 2026-09-03 Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: …
CVE-2026-85306 MEDIUM 6.5 2026-09-03 Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels…
CVE-2026-85305 MEDIUM 5.4 2026-09-03 Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1.
CVE-2026-85304 MEDIUM 5.3 2026-09-03 Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access…
CVE-2026-85303 MEDIUM 6.5 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This is…
CVE-2026-85302 MEDIUM 6.5 2026-09-03 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based …
CVE-2026-85242 NONE — 2026-09-03 PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application va…
CVE-2026-85241 MEDIUM 6.3 2026-09-03 A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the com…
CVE-2026-85239 NONE — 2026-09-03 A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template def…
CVE-2026-85238 NONE — 2026-09-03 MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth…
CVE-2026-85237 NONE — 2026-09-03 A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The …
CVE-2026-85236 NONE — 2026-09-03 A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while ac…
CVE-2026-85230 NONE — 2026-09-03 A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rende…