Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 2,281 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2025-15693 | LOW | Patched | 2.7 | 2026-09-05 | The JCH Optimize WordPress plugin before 5.0.1 does not properly restrict a directory path provided to one of its administrative image-browsing features to within the site,… |
| CVE-2025-15694 | LOW | Patched | 3.5 | 2026-09-05 | The Joli Table Of Contents WordPress plugin before 2.8.1 does not sanitise and escape some of its settings before outputting them in an admin page, which could allow high-p… |
| CVE-2025-46418 | HIGH | 7.6 | 2026-09-02 | Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition. | |
| CVE-2025-52651 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Improper Input validation Vulnerability. It allow malicious or unexpected data to cause unintended system behaviour or security issues. | |
| CVE-2025-52652 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Content Spoofing Vulnerability. It may allow an attacker to manipulate displayed content, making it appear as though it originates from a tru… | |
| CVE-2025-52657 | LOW | 3.5 | 2026-09-07 | HCL MyXalytics was affected by Potential DOS Vulnerability. It allows users to input data without any restriction on the number of characters which can impact system perfor… | |
| CVE-2025-67066 | NONE | — | 2026-09-04 | SQL Injection vulnerability in oasys sysoa version 1.0 allows a remote attacker to execute arbitrary code via the outtype parameter in the /outaddresspaging path | |
| CVE-2025-7963 | MEDIUM | 6.4 | 2026-09-02 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and includ… | |
| CVE-2025-8945 | MEDIUM | Patched | 5.3 | 2026-09-02 | The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API. |
| CVE-2025-9049 | HIGH | 8.8 | 2026-09-05 | The Nokri – Job Board WordPress Theme theme for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'nokri_account_member_… | |
| CVE-2025-9314 | CRITICAL | 9.8 | 2026-09-02 | The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component | |
| CVE-2026-0799 | HIGH | 8.7 | 2026-09-05 | In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF inter… | |
| CVE-2026-10195 | HIGH | 8.8 | 2026-09-01 | The FS-Poster plugin for WordPress is vulnerable to Remote Code Execution in versions up to and including 8.0.1. This is due to insufficient input sanitization of the FFmpe… | |
| CVE-2026-10196 | CRITICAL | Patched | 9.8 | 2026-09-05 | The Mail Mint – Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and inc… |
| CVE-2026-10420 | MEDIUM | Patched | 5.5 | 2026-09-01 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. |
| CVE-2026-10821 | MEDIUM | Patched | 6.6 | 2026-09-02 | The Yoast SEO Premium WordPress plugin before 27.6.1 does not sanitize control characters from redirect origins before writing them to the site's Apache configuration file … |
| CVE-2026-11613 | CRITICAL | 9.8 | 2026-09-04 | The Divi Ajax Filter plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 5.1.2 via the 'custom_loop_template' parameter paramet… | |
| CVE-2026-11873 | MEDIUM | 6.5 | 2026-09-01 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request… | |
| CVE-2026-12483 | HIGH | 7.5 | 2026-09-04 | The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in… | |
| CVE-2026-12526 | HIGH | Patched | 8.1 | 2026-09-02 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user a… |
| CVE-2026-12661 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to th… | |
| CVE-2026-12663 | NONE | — | 2026-09-01 | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb… | |
| CVE-2026-12704 | MEDIUM | 6.8 | 2026-09-02 | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated lo… | |
| CVE-2026-12747 | MEDIUM | 6.4 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.… | |
| CVE-2026-12757 | MEDIUM | 6.5 | 2026-09-07 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode ex… |