Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,281 CVEs

CVEs (2,281, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 51–75 of 2,281 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-77189 MEDIUM 6.5 2026-09-01 The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection v…
CVE-2026-83772 CRITICAL 9.9 2026-09-01 A vulnerability was detected in Cobham SATCOM VSAT7090 Maritime Satellite Router up to 20260704. This issue affects the function c_set_reports_decode of the file mail-repor…
CVE-2026-78319 NONE — 2026-09-01 A service running on the affected products contains a potential Time-of-Check Time-of-Use (TOCTOU) race condition. An unauthenticated remote attacker could exploit this rac…
CVE-2026-13611 MEDIUM Patched 5.3 2026-09-01 The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient r…
CVE-2026-74916 MEDIUM Patched 6.5 2026-09-01 The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested wit…
CVE-2026-78363 MEDIUM Patched 4.8 2026-09-01 The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it lat…
CVE-2026-15101 MEDIUM 6.4 2026-09-01 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu…
CVE-2026-16786 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve…
CVE-2026-16788 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio…
CVE-2026-19914 HIGH 7.2 2026-09-01 The Welcart e-Commerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_order' parameter in all versions up to, and including, 2.12.1 due t…
CVE-2026-25706 HIGH 7.5 2026-09-01 Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - …
CVE-2026-59680 HIGH 8.0 2026-09-01 An OS command injection vulnerability was found in yast2-users. When displaying the "Password Settings" tab of a user, get_password_term() in src/include/users/dialogs.rb r…
CVE-2026-59681 HIGH 8.8 2026-09-01 A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the…
CVE-2026-4813 NONE — 2026-09-01 A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT proces…
CVE-2026-82926 MEDIUM 5.5 2026-09-01 NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.
CVE-2026-82927 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.
CVE-2026-84059 HIGH 7.4 2026-09-01 A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260704. The affected element is the function ArmAngstromInstructionSet of the file /CGI?RestApi=SetHostname. Ex…
CVE-2026-84165 NONE — 2026-09-01 A vulnerability relating to incorrect access control in OpenNebula by OpenNebula Systems, affecting all versions prior to 7.4. This vulnerability could allow an authenticat…
CVE-2023-54356 LOW Patched 3.7 2026-09-01 Kyverno versions 1.9.4 and earlier support insecure 3DES cipher suites (TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA and TLS_RSA_WITH_3DES_EDE_CBC_SHA) on their TLS endpoints. These…
CVE-2025-15613 MEDIUM 6.5 2026-09-01 Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici…
CVE-2026-10420 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 102d3dc75cf8e58e68e4bea54ae3c803992c91be.
CVE-2026-11873 MEDIUM 6.5 2026-09-01 An Apache-proxied Dogtag CA REST endpoint exposed by IdM (POST /ca/rest/certrequests) returns HTTP 500 with internal Java stack traces for unauthenticated malformed request…
CVE-2026-18550 CRITICAL 9.8 2026-09-01 The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i…
CVE-2026-76111 HIGH 8.8 2026-09-01 Dell PowerStore contains an Incorrect Authorization vulnerability. An authenticated attacker with low privileges could potentially exploit this vulnerability to invoke admi…
CVE-2026-77194 MEDIUM Patched 5.3 2026-09-01 The Simple Membership plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in versions up to, and including, 4.8.0. This is…