Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-12483 | HIGH | 7.5 | 2026-09-04 | The LearnDash LMS plugin for WordPress is vulnerable to Unrestricted File Type Upload in versions up to and including 5.1.5. This is due to insufficient input validation in… | |
| CVE-2026-12526 | HIGH | Patched | 8.1 | 2026-09-02 | The Advanced Custom Fields: Extended WordPress plugin before 0.9.2.7 does not verify that the requester is authorized to edit the targeted user account in the update-user a… |
| CVE-2026-12611 | NONE | — | 2026-09-08 | A client may issue HTTP/2 requests to a Jetty server that result in blocking writes that are never unblocked, eventually causing all threads to be blocked and the whole ser… | |
| CVE-2026-12645 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12646 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12647 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Missing Authorization vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12648 | HIGH | Patched | 8.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12650 | CRITICAL | Patched | 9.9 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12651 | HIGH | Patched | 8.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote authenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12661 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to th… | |
| CVE-2026-12663 | NONE | — | 2026-09-01 | A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arb… | |
| CVE-2026-12704 | MEDIUM | 6.8 | 2026-09-02 | When SAML IdP-initiated login is enabled in Grafana Enterprise, the SAML library skips validation of the InResponseTo field on all SAML responses, including SP-initiated lo… | |
| CVE-2026-12744 | CRITICAL | Patched | 9.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12745 | CRITICAL | Patched | 9.8 | 2026-09-08 | A Deserialization of Untrusted Data vulnerability in Ivanti Neurons for ITSM before 2026.2 allows a remote unauthenticated attacker to execute arbitrary code on the server. |
| CVE-2026-12747 | MEDIUM | 6.4 | 2026-09-01 | The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.… | |
| CVE-2026-12757 | MEDIUM | 6.5 | 2026-09-07 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode ex… | |
| CVE-2026-12843 | MEDIUM | 5.4 | 2026-09-05 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is aut… | |
| CVE-2026-12853 | MEDIUM | 5.4 | 2026-09-07 | The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a… | |
| CVE-2026-12865 | HIGH | Patched | 7.1 | 2026-09-02 | The Photo Gallery by 10Web WordPress plugin before 1.8.44 does not escape two request parameters before reflecting them into input-attribute values on its admin pages (one… |
| CVE-2026-12962 | NONE | — | 2026-09-08 | A Permissive Cross-domain Security Policy with Untrusted Domains in Armoury Crate allows a remote user to obtain a local user's NTLM hash by convincing the user to visit a … | |
| CVE-2026-13148 | NONE | Patched | — | 2026-09-04 | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10. |
| CVE-2026-13159 | MEDIUM | 4.3 | 2026-09-06 | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscri… | |
| CVE-2026-13203 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_mod… | |
| CVE-2026-13297 | NONE | — | 2026-09-04 | IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack. | |
| CVE-2026-13336 | NONE | — | 2026-09-01 | CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could cause execution of Linux Operating system… |