Search
78,402 CVEs
EOL hidden · Show all products
CVEs (78,402, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 476–500 of 78,402 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86119 | HIGH | 8.6 | 2026-09-05 | Webstudio through 0.296.0 contains an unauthenticated server-side request forgery vulnerability in the /cgi/image, /cgi/video, and /cgi/asset proxy routes when RESIZE_ORIGI… | |
| CVE-2026-86118 | MEDIUM | Patched | 4.3 | 2026-09-05 | gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attacker… |
| CVE-2026-86117 | HIGH | 8.1 | 2026-09-05 | Coolify through 4.3.17 contains an authentication bypass vulnerability in the OAuth callback handler that signs users into existing accounts based solely on email address w… | |
| CVE-2026-86116 | MEDIUM | Patched | 6.5 | 2026-09-05 | Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glos… |
| CVE-2026-86115 | MEDIUM | Patched | 5.0 | 2026-09-05 | Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authenticati… |
| CVE-2026-86114 | MEDIUM | Patched | 6.5 | 2026-09-05 | Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including in… |
| CVE-2026-86113 | MEDIUM | 6.5 | 2026-09-05 | BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading record… | |
| CVE-2026-86112 | MEDIUM | 5.4 | 2026-09-05 | BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite follow… | |
| CVE-2026-86111 | MEDIUM | 6.5 | 2026-09-05 | BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message… | |
| CVE-2026-76573 | MEDIUM | 6.4 | 2026-09-05 | The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and … | |
| CVE-2024-11080 | CRITICAL | 9.8 | 2026-09-05 | The Post Grid and Gutenberg Blocks – ComboBlocks plugin for WordPress is vulnerable to Unauthenticated Hook Injection in versions 2.2.32 to 2.3.1 via several functions in t… | |
| CVE-2026-85414 | MEDIUM | 6.4 | 2026-09-05 | The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3… | |
| CVE-2026-83625 | HIGH | 7.2 | 2026-09-05 | The Contact Form by Supsystic plugin for WordPress is vulnerable to Stored Cross-Site Scripting via IP Address Header in all versions up to, and including, 1.10.2 due to in… | |
| CVE-2026-81543 | HIGH | 8.8 | 2026-09-05 | The Abandoned Cart Pro for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 10.7.1. This is due to missing capab… | |
| CVE-2026-75586 | MEDIUM | 6.1 | 2026-09-05 | The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including,… | |
| CVE-2026-75018 | MEDIUM | 4.3 | 2026-09-05 | The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verif… | |
| CVE-2026-84937 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users wit… |
| CVE-2026-84936 | MEDIUM | Patched | 5.3 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make… |
| CVE-2026-84935 | HIGH | Patched | 8.0 | 2026-09-05 | The HT Menu WordPress plugin before 1.2.7 does not perform any capability or object-ownership check when saving navigation menu-item settings, and does not escape those st… |
| CVE-2026-84934 | HIGH | Patched | 8.0 | 2026-09-05 | The JCH Optimize WordPress plugin before 6.0.1 does not perform a capability check on one of its authenticated AJAX actions and lets the request choose which internal actio… |
| CVE-2026-84931 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, al… |
| CVE-2026-84930 | MEDIUM | Patched | 6.8 | 2026-09-05 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery … |
| CVE-2026-84927 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not perform a sufficient authorization check on one of its Google Reviews REST API routes, allowing users with the Contri… |
| CVE-2026-84926 | LOW | Patched | 2.7 | 2026-09-05 | The EmbedPress WordPress plugin before 4.6.4 does not correctly restrict access to one of its Google Reviews REST routes to administrators, allowing any authenticated user… |
| CVE-2026-84901 | MEDIUM | Patched | 4.9 | 2026-09-05 | The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level acce… |