Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,841 CVEs

CVEs (9,841, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 9,841 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9585 NONE — 2026-07-17 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti…
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?…
CVE-2026-9576 MEDIUM Patched 4.9 2026-06-30 The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users…
CVE-2026-9571 MEDIUM Patched 5.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivat&hellip;
CVE-2026-9563 HIGH 7.5 2026-07-02 In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while pars&hellip;
CVE-2026-9561 NONE &mdash; 2026-07-14 Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The or&hellip;
CVE-2026-9547 HIGH Patched 7.4 2026-07-03 When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted serve&hellip;
CVE-2026-9546 HIGH Patched 7.5 2026-07-03 A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` &hellip;
CVE-2026-9545 HIGH Patched 7.5 2026-07-03 In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the atta&hellip;
CVE-2026-9539 MEDIUM 6.5 2026-06-24 An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environmen&hellip;
CVE-2026-9537 MEDIUM Patched 5.3 2026-07-17 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom&hellip;
CVE-2026-9499 NONE &mdash; 2026-07-21 An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated &hellip;
CVE-2026-9494 MEDIUM 5.5 2026-07-16 An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executin&hellip;
CVE-2026-9492 HIGH 7.8 2026-07-13 The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated&hellip;
CVE-2026-9341 MEDIUM 4.3 2026-07-14 The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc&hellip;
CVE-2026-9323 HIGH 8.1 2026-07-18 The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that &hellip;
CVE-2026-9292 NONE &mdash; 2026-07-14 A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied inp&hellip;
CVE-2026-9282 HIGH 7.5 2026-07-11 The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possib&hellip;
CVE-2026-9272 HIGH Patched 8.1 2026-07-02 In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detect&hellip;
CVE-2026-9267 NONE &mdash; 2026-06-29 Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows &hellip;
CVE-2026-9263 MEDIUM Patched 6.5 2026-06-30 The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per t&hellip;
CVE-2026-9253 HIGH 7.2 2026-07-09 The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versio&hellip;
CVE-2026-9242 MEDIUM 5.3 2026-06-27 The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient V&hellip;
CVE-2026-9240 MEDIUM 4.3 2026-07-09 The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on&hellip;
CVE-2026-9237 MEDIUM 4.3 2026-07-09 The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. Thi&hellip;