Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,503 CVEs · Medium severity

CVEs (163,503, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 163,503 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9722 MEDIUM 4.3 2026-06-02 The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce valid…
CVE-2026-9721 MEDIUM 4.3 2026-06-24 The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre…
CVE-2026-9720 MEDIUM 4.3 2026-07-29 The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing …
CVE-2026-9719 MEDIUM 4.3 2026-06-06 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5…
CVE-2026-9718 MEDIUM Patched 6.5 2026-06-25 CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s…
CVE-2026-9714 MEDIUM 6.4 2026-05-29 The Simple Divi Shortcode plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' parameter of the [showmodule] shortcode in versions up to, and incl…
CVE-2026-9708 MEDIUM Patched 4.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel&hellip;
CVE-2026-9705 MEDIUM Patched 6.5 2026-06-25 A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerabil&hellip;
CVE-2026-9704 MEDIUM 6.8 2026-05-27 A flaw was found in Keycloak. An authenticated user with low privileges can exploit this vulnerability by sending an oversized subject_token JSON Web Token (JWT) to the Tok&hellip;
CVE-2026-9699 MEDIUM 6.8 2026-06-26 Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server l&hellip;
CVE-2026-9692 MEDIUM 5.3 2026-06-18 Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built&hellip;
CVE-2026-9689 MEDIUM 4.2 2026-05-27 A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform Resource Iden&hellip;
CVE-2026-9680 MEDIUM 5.8 2026-07-28 Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listeni&hellip;
CVE-2026-9679 MEDIUM Patched 5.9 2026-06-17 Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal b&hellip;
CVE-2026-9678 MEDIUM Patched 5.9 2026-06-17 Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-&hellip;
CVE-2026-9677 MEDIUM 4.8 2026-06-27 The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via &hellip;
CVE-2026-9676 MEDIUM Patched 4.3 2026-06-29 The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with S&hellip;
CVE-2026-9674 MEDIUM Patched 4.3 2026-05-27 A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.
CVE-2026-9673 MEDIUM Patched 6.8 2026-05-28 Versions of the package json-2-csv from 3.15.0 and before 5.5.11 are vulnerable to CSV Injection via the preventCsvInjection option which can be bypassed. An attacker can i&hellip;
CVE-2026-9668 MEDIUM 6.3 2026-08-26 With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. T&hellip;
CVE-2026-9656 MEDIUM 4.3 2026-07-17 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.&hellip;
CVE-2026-9651 MEDIUM Patched 4.4 2026-06-25 CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise whe&hellip;
CVE-2026-9646 MEDIUM 6.1 2026-05-28 A reflected cross-site scripting issue exists in URL handling.
CVE-2026-9644 MEDIUM 6.4 2026-05-28 The LiveSmart Video Chat Live Video Chat plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'livesmart_widget' shortcode in all versions up &hellip;
CVE-2026-9641 MEDIUM Patched 5.3 2026-06-12 Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for l&hellip;