Search
2,281 CVEs
CVEs (2,281, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 51–75 of 2,281 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-77189 | MEDIUM | 6.5 | 2026-09-01 | The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection v… | |
| CVE-2026-83772 | CRITICAL | 9.9 | 2026-09-01 | A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-repor… | |
| CVE-2026-78319 | NONE | — | 2026-09-01 | A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this rac… | |
| CVE-2026-13611 | MEDIUM | Patched | 5.3 | 2026-09-01 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient r… |
| CVE-2026-74916 | MEDIUM | Patched | 6.5 | 2026-09-01 | The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested wit… |
| CVE-2026-78363 | MEDIUM | Patched | 4.8 | 2026-09-01 | The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it lat… |
| CVE-2026-15101 | MEDIUM | 6.4 | 2026-09-01 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu… | |
| CVE-2026-16786 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve… | |
| CVE-2026-16788 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio… | |
| CVE-2026-19914 | HIGH | 7.2 | 2026-09-01 | The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due t… | |
| CVE-2026-25706 | HIGH | 7.5 | 2026-09-01 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - … | |
| CVE-2026-59680 | HIGH | 8.0 | 2026-09-01 | An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb r… | |
| CVE-2026-59681 | HIGH | 8.8 | 2026-09-01 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the… | |
| CVE-2026-4813 | NONE | — | 2026-09-01 | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces… | |
| CVE-2026-82926 | MEDIUM | 5.5 | 2026-09-01 | NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a. | |
| CVE-2026-82927 | MEDIUM | Patched | 5.5 | 2026-09-01 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e. |
| CVE-2026-84059 | HIGH | 7.4 | 2026-09-01 | A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Ex… | |
| CVE-2026-84165 | NONE | — | 2026-09-01 | A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticat… | |
| CVE-2023-54356 | LOW | Patched | 3.7 | 2026-09-01 | Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These… |
| CVE-2025-15613 | MEDIUM | 6.5 | 2026-09-01 | Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici… | |
| CVE-2026-10420 | MEDIUM | Patched | 5.5 | 2026-09-01 | Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be. |
| CVE-2026-11873 | MEDIUM | 6.5 | 2026-09-01 | An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request… | |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-76111 | HIGH | 8.8 | 2026-09-01 | Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi… | |
| CVE-2026-77194 | MEDIUM | Patched | 5.3 | 2026-09-01 | The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is… |