Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 9,841 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9585 | NONE | — | 2026-07-17 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti… | |
| CVE-2026-9577 | MEDIUM | Patched | 4.8 | 2026-07-23 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?… |
| CVE-2026-9576 | MEDIUM | Patched | 4.9 | 2026-06-30 | The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users… |
| CVE-2026-9571 | MEDIUM | Patched | 5.9 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivat… |
| CVE-2026-9563 | HIGH | 7.5 | 2026-07-02 | In Eclipse Parsson published Maven Central artifacts before version 1.1.8, the JSON parser did not enforce a default maximum on the number of characters consumed while pars… | |
| CVE-2026-9561 | NONE | — | 2026-07-14 | Eclipse Kura versions prior to 5.6.2 trust the client-supplied X-Forwarded-For HTTP header as the authoritative source of the client IP address in audit log entries. The or… | |
| CVE-2026-9547 | HIGH | Patched | 7.4 | 2026-07-03 | When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted serve… |
| CVE-2026-9546 | HIGH | Patched | 7.5 | 2026-07-03 | A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` … |
| CVE-2026-9545 | HIGH | Patched | 7.5 | 2026-07-03 | In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the atta… |
| CVE-2026-9539 | MEDIUM | 6.5 | 2026-06-24 | An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environmen… | |
| CVE-2026-9537 | MEDIUM | Patched | 5.3 | 2026-07-17 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom… |
| CVE-2026-9499 | NONE | — | 2026-07-21 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated … | |
| CVE-2026-9494 | MEDIUM | 5.5 | 2026-07-16 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executin… | |
| CVE-2026-9492 | HIGH | 7.8 | 2026-07-13 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated… | |
| CVE-2026-9341 | MEDIUM | 4.3 | 2026-07-14 | The Academy LMS – WordPress LMS Plugin for Complete eLearning Solution plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and inc… | |
| CVE-2026-9323 | HIGH | 8.1 | 2026-07-18 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that … | |
| CVE-2026-9292 | NONE | — | 2026-07-14 | A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied inp… | |
| CVE-2026-9282 | HIGH | 7.5 | 2026-07-11 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possib… | |
| CVE-2026-9272 | HIGH | Patched | 8.1 | 2026-07-02 | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detect… |
| CVE-2026-9267 | NONE | — | 2026-06-29 | Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows … | |
| CVE-2026-9263 | MEDIUM | Patched | 6.5 | 2026-06-30 | The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per t… |
| CVE-2026-9253 | HIGH | 7.2 | 2026-07-09 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versio… | |
| CVE-2026-9242 | MEDIUM | 5.3 | 2026-06-27 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient V… | |
| CVE-2026-9240 | MEDIUM | 4.3 | 2026-07-09 | The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | |
| CVE-2026-9237 | MEDIUM | 4.3 | 2026-07-09 | The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. Thi… |