Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 2,372 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-85390 | HIGH | 7.1 | 2026-09-03 | Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform admin… | |
| CVE-2026-85389 | MEDIUM | Patched | 6.5 | 2026-09-03 | Worklenz before 3.0.0 fails to verify task ownership by organization when resolving task-scoped API endpoints, allowing authenticated users to access another tenant's task … |
| CVE-2026-85388 | HIGH | 8.1 | 2026-09-03 | Worklenz through 3.0.0 fails to properly validate the sort-field query parameter in pagination helper functions, allowing authenticated users to inject arbitrary PostgreSQL… | |
| CVE-2026-85383 | MEDIUM | 6.3 | 2026-09-04 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/inv_del.php. Executing a manipulation o… | |
| CVE-2026-85382 | MEDIUM | 4.3 | 2026-09-04 | A vulnerability was detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Impacted is the function htmlspecialchars_d… | |
| CVE-2026-85381 | MEDIUM | 5.3 | 2026-09-04 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This issue affects some unkno… | |
| CVE-2026-85380 | HIGH | 7.3 | 2026-09-04 | A weakness has been identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects the function c… | |
| CVE-2026-85379 | HIGH | 7.3 | 2026-09-04 | A security flaw has been discovered in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This affects the function ChapterMod… | |
| CVE-2026-85378 | HIGH | 7.3 | 2026-09-03 | A vulnerability was identified in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Au… | |
| CVE-2026-85311 | MEDIUM | 5.3 | 2026-09-04 | Missing Authorization vulnerability in Kings Plugins MarketKing allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects MarketKing: fro… | |
| CVE-2026-85309 | MEDIUM | 5.3 | 2026-09-03 | Missing Authorization vulnerability in Supsystic Ultimate Maps by Supsystic allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Ult… | |
| CVE-2026-85308 | MEDIUM | 5.3 | 2026-09-03 | Authorization Bypass Through User-Controlled Key vulnerability in Brainstorm Force SureForms allows Exploiting Incorrectly Configured Access Control Security Levels. This … | |
| CVE-2026-85307 | MEDIUM | Patched | 5.3 | 2026-09-03 | Insertion of Sensitive Information Into Sent Data vulnerability in Kevin Pirnie KP Agent Ready allows Retrieve Embedded Sensitive Data. This issue affects KP Agent Ready: … |
| CVE-2026-85306 | MEDIUM | 6.5 | 2026-09-03 | Missing Authorization vulnerability in Cascadia Web Services MountDev AI MCP Connector for WordPress allows Exploiting Incorrectly Configured Access Control Security Levels… | |
| CVE-2026-85305 | MEDIUM | 5.4 | 2026-09-03 | Server-Side Request Forgery (SSRF) vulnerability in SEOPress allows Server Side Request Forgery. This issue affects SEOPress: from n/a through 10.1. | |
| CVE-2026-85304 | MEDIUM | 5.3 | 2026-09-03 | Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) allows Exploiting Incorrectly Configured Access… | |
| CVE-2026-85303 | MEDIUM | 6.5 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Booking and Rental Manager allows Stored XSS. This is… | |
| CVE-2026-85302 | MEDIUM | 6.5 | 2026-09-03 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPKoi WordPress Themes WPKoi Templates for Elementor allows DOM-Based … | |
| CVE-2026-85242 | NONE | — | 2026-09-03 | PlaywrightCapture contains a server-side request forgery (SSRF) vulnerability in its favicon retrieval functionality. When only_global_lookup is enabled, the application va… | |
| CVE-2026-85241 | MEDIUM | 6.3 | 2026-09-03 | A weakness has been identified in SpecterOps BloodHound up to 9.5.1. The affected element is the function NewV2API of the file cmd/api/src/api/registration/v2.go of the com… | |
| CVE-2026-85239 | NONE | — | 2026-09-03 | A vulnerability in MISP's event template handling allowed an authenticated user with permission to create or modify event templates to bypass validation of the template def… | |
| CVE-2026-85238 | NONE | — | 2026-09-03 | MISP contains a session fixation vulnerability in the CustomAuth authentication (a custom configuration) flow. When a user was successfully authenticated through CustomAuth… | |
| CVE-2026-85237 | NONE | — | 2026-09-03 | A vulnerability in MISP's email-based one-time password (OTP) authentication flow allowed an attacker to perform an unrestricted number of OTP verification attempts. The … | |
| CVE-2026-85236 | NONE | — | 2026-09-03 | A cross-site request forgery (CSRF) vulnerability existed in the cullEmptyEvents action of MISP. The endpoint performed a state-changing and irreversible operation while ac… | |
| CVE-2026-85230 | NONE | — | 2026-09-03 | A persistent unsafe URL injection vulnerability exists in the MISP dashboard ButtonWidget configuration. Dashboard widget URLs were validated only when the widget was rende… |