Search
30,126 CVEs
CVEs (30,126, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 30,126 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-12034 | HIGH | Patched | 8.3 | 2026-06-11 | Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the rend… |
| CVE-2026-12035 | HIGH | Patched | 8.8 | 2026-06-11 | Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chrom… |
| CVE-2026-39494 | CRITICAL | 9.3 | 2026-06-11 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This is… | |
| CVE-2026-42647 | CRITICAL | 9.3 | 2026-06-11 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects Joom… | |
| CVE-2026-42653 | HIGH | 7.1 | 2026-06-11 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This issue affects SliceWP: fro… | |
| CVE-2026-44249 | HIGH | Patched | 8.1 | 2026-06-11 | Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can… |
| CVE-2026-44250 | HIGH | Patched | 7.5 | 2026-06-11 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker… |
| CVE-2026-44890 | HIGH | Patched | 7.5 | 2026-06-11 | Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker… |
| CVE-2026-45171 | HIGH | Patched | 8.8 | 2026-06-11 | Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5,… |
| CVE-2026-45172 | HIGH | Patched | 8.8 | 2026-06-11 | Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged… |
| CVE-2026-45173 | MEDIUM | Patched | 6.5 | 2026-06-11 | Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification rou… |
| CVE-2026-45174 | HIGH | Patched | 7.8 | 2026-06-11 | Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bull… |
| CVE-2026-49060 | CRITICAL | 9.8 | 2026-06-11 | Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n… | |
| CVE-2026-6250 | HIGH | Patched | 8.1 | 2026-06-11 | An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input. Externally controlled data is i… |
| CVE-2026-42846 | CRITICAL | Patched | 9.8 | 2026-06-11 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by impo… |
| CVE-2026-45060 | CRITICAL | Patched | 9.8 | 2026-06-11 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any una… |
| CVE-2026-45418 | HIGH | Patched | 8.8 | 2026-06-11 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from differen… |
| CVE-2026-47238 | MEDIUM | Patched | 6.5 | 2026-06-11 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack… |
| CVE-2026-10676 | NONE | — | 2026-06-12 | Rejected reason: This CVE Record has been rejected by the Zephyr Project CNA. Subsequent analysis determined that the addressed defect is not reachable in any released vers… | |
| CVE-2026-49482 | MEDIUM | Patched | 4.3 | 2026-06-12 | ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the s… |
| CVE-2026-11933 | HIGH | Patched | 8.8 | 2026-06-12 | A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read… |
| CVE-2026-45170 | HIGH | Patched | 8.8 | 2026-06-12 | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforc… |
| CVE-2026-9125 | MEDIUM | 6.4 | 2026-06-12 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to,… | |
| CVE-2026-20746 | NONE | — | 2026-06-12 | Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled… | |
| CVE-2026-47365 | CRITICAL | Patched | 9.9 | 2026-06-12 | Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and exec… |