Search
158,556 CVEs · Medium severity
CVEs (158,556, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 158,556 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9751 | MEDIUM | Patched | 5.5 | 2026-06-09 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text. |
| CVE-2026-9750 | MEDIUM | Patched | 6.5 | 2026-06-09 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query ex… |
| CVE-2026-9749 | MEDIUM | Patched | 6.5 | 2026-06-09 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a … |
| CVE-2026-9748 | MEDIUM | Patched | 6.5 | 2026-06-09 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a g… |
| CVE-2026-9747 | MEDIUM | Patched | 6.5 | 2026-06-09 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. |
| CVE-2026-9746 | MEDIUM | Patched | 6.5 | 2026-06-09 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special pr… |
| CVE-2026-9743 | MEDIUM | Patched | 6.5 | 2026-06-09 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cu… |
| CVE-2026-9741 | MEDIUM | Patched | 6.5 | 2026-06-09 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal va… |
| CVE-2026-9738 | MEDIUM | 4.4 | 2026-07-11 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and… | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-9735 | MEDIUM | Patched | 5.5 | 2026-06-09 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the… |
| CVE-2026-9734 | MEDIUM | 4.3 | 2026-07-18 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor… | |
| CVE-2026-9732 | MEDIUM | 4.3 | 2026-06-03 | The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This … | |
| CVE-2026-9731 | MEDIUM | 4.3 | 2026-07-08 | The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce val… | |
| CVE-2026-9730 | MEDIUM | 4.3 | 2026-06-02 | The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or inco… | |
| CVE-2026-9729 | MEDIUM | 6.4 | 2026-07-23 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par… | |
| CVE-2026-9724 | MEDIUM | 4.3 | 2026-06-24 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida… | |
| CVE-2026-9723 | MEDIUM | 4.3 | 2026-06-02 | The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect… | |
| CVE-2026-9722 | MEDIUM | 4.3 | 2026-06-02 | The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce valid… | |
| CVE-2026-9721 | MEDIUM | 4.3 | 2026-06-24 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre… | |
| CVE-2026-9719 | MEDIUM | 4.3 | 2026-06-06 | The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5… | |
| CVE-2026-9718 | MEDIUM | Patched | 6.5 | 2026-06-25 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s… |
| CVE-2026-9714 | MEDIUM | 6.4 | 2026-05-29 | The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and incl… | |
| CVE-2026-9708 | MEDIUM | Patched | 4.9 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel… |
| CVE-2026-9705 | MEDIUM | Patched | 6.5 | 2026-06-25 | A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerabil… |