Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,281 CVEs

CVEs (2,281, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 2,281 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2025-15693 LOW Patched 2.7 2026-09-05 The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,…
CVE-2025-15694 LOW Patched 3.5 2026-09-05 The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p…
CVE-2025-46418 HIGH 7.6 2026-09-02 Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
CVE-2025-52651 LOW 3.5 2026-09-07 HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues.
CVE-2025-52652 LOW 3.5 2026-09-07 HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a tru…
CVE-2025-52657 LOW 3.5 2026-09-07 HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system perfor…
CVE-2025-67066 NONE — 2026-09-04 SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path
CVE-2025-7963 MEDIUM 6.4 2026-09-02 The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and includ…
CVE-2025-8945 MEDIUM Patched 5.3 2026-09-02 The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.
CVE-2025-9049 HIGH 8.8 2026-09-05 The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_…
CVE-2025-9314 CRITICAL 9.8 2026-09-02 The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component
CVE-2026-0799 HIGH 8.7 2026-09-05 In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF inter…
CVE-2026-10195 HIGH 8.8 2026-09-01 The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpe…
CVE-2026-10196 CRITICAL Patched 9.8 2026-09-05 The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc…
CVE-2026-10420 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
CVE-2026-10821 MEDIUM Patched 6.6 2026-09-02 The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file …
CVE-2026-11613 CRITICAL 9.8 2026-09-04 The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter paramet…
CVE-2026-11873 MEDIUM 6.5 2026-09-01 An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request…
CVE-2026-12483 HIGH 7.5 2026-09-04 The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in…
CVE-2026-12526 HIGH Patched 8.1 2026-09-02 The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user a…
CVE-2026-12661 NONE — 2026-09-01 A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition.  A network adjacent attacker who is authenticated could send crafted requests to th…
CVE-2026-12663 NONE — 2026-09-01 A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb…
CVE-2026-12704 MEDIUM 6.8 2026-09-02 When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated lo…
CVE-2026-12747 MEDIUM 6.4 2026-09-01 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.…
CVE-2026-12757 MEDIUM 6.5 2026-09-07 The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode ex…