Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 9,831 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-9184 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu… | |
| CVE-2026-9612 | MEDIUM | 5.3 | 2026-06-24 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y… | |
| CVE-2026-9616 | MEDIUM | 4.3 | 2026-06-24 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve… | |
| CVE-2026-9619 | MEDIUM | 4.3 | 2026-06-24 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not pr… | |
| CVE-2026-9620 | MEDIUM | 6.4 | 2026-06-24 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0… | |
| CVE-2026-9643 | HIGH | 7.2 | 2026-06-24 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, … | |
| CVE-2026-9709 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of … |
| CVE-2026-9710 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to ever… |
| CVE-2026-9721 | MEDIUM | 4.3 | 2026-06-24 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre… | |
| CVE-2026-9724 | MEDIUM | 4.3 | 2026-06-24 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida… | |
| CVE-2026-52912 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the i… |
| CVE-2026-52913 | MEDIUM | Patched | 5.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: stop OGMv2 on disabled interface When a batadv_hard_iface is disabled, its mesh_iface p… |
| CVE-2026-52914 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix fragment reassembly length accounting batman-adv keeps a running payload length for qu… |
| CVE-2026-52915 | HIGH | Patched | 7.1 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ip6t_hbh: reject oversized option lists struct ip6t_opts stores at most IP6T_OPTS_OPTSNR op… |
| CVE-2026-52916 | MEDIUM | Patched | 5.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: frag: disallow unicast fragment in fragment batadv_frag_skb_buffer() is called by batadv_b… |
| CVE-2026-52917 | HIGH | Patched | 7.1 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: sctp: diag: reject stale associations in dump_one path The SCTP exact sock_diag lookup can hold a tran… |
| CVE-2026-52918 | HIGH | Patched | 8.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: Bluetooth: serialize accept_q access bt_sock_poll() walks the accept queue without synchronization, wh… |
| CVE-2026-52919 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: fix tp_meter counter underflow during shutdown batadv_tp_sender_shutdown() unconditionally… |
| CVE-2026-52920 | HIGH | Patched | 8.3 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries… |
| CVE-2026-52921 | MEDIUM | Patched | 5.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: netfilter: ipset: stop hash:* range iteration at end The following hash set variants: hash:ip,mark ha… |
| CVE-2026-52922 | HIGH | Patched | 7.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: handle forward allocation error batadv_dat_forward_data() calls pskb_copy_for_clone()… |
| CVE-2026-52923 | HIGH | Patched | 7.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: ipc: limit next_id allocation to the valid ID range The checkpoint/restore sysctl path can request the… |
| CVE-2026-52924 | CRITICAL | Patched | 9.8 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: sctp: purge outqueue on stale COOKIE-ECHO handling sctp_stream_update() is only invoked when the assoc… |
| CVE-2026-52925 | MEDIUM | Patched | 5.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: vrf: Fix a potential NPD when removing a port from a VRF RCU readers that identified a net device as a… |
| CVE-2026-52926 | MEDIUM | Patched | 5.5 | 2026-06-24 | In the Linux kernel, the following vulnerability has been resolved: batman-adv: clear current gateway during teardown batadv_gw_node_free() removes the gateway list entri… |