Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 76–100 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9701 CRITICAL 9.8 2026-07-08 The Eventer plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 4.4.2. The plugin stores a plaintext copy of th…
CVE-2026-9700 HIGH 7.5 2026-07-08 The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping…
CVE-2026-9699 MEDIUM 6.8 2026-06-26 Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server l&hellip;
CVE-2026-9697 HIGH Patched 7.4 2026-06-17 Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SO&hellip;
CVE-2026-9695 CRITICAL 9.8 2026-07-08 An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to the server.
CVE-2026-9694 LOW Patched 2.6 2026-06-11 GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, &hellip;
CVE-2026-9693 LOW Patched 3.5 2026-08-17 Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, which allows a &hellip;
CVE-2026-9692 MEDIUM 5.3 2026-06-18 Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded with the built&hellip;
CVE-2026-9691 CRITICAL 9.8 2026-06-15 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
CVE-2026-9690 HIGH 7.5 2026-06-17 Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
CVE-2026-9680 MEDIUM 5.8 2026-07-28 Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP tools via network access to an MCP endpoint listeni&hellip;
CVE-2026-9679 MEDIUM Patched 5.9 2026-06-17 Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal b&hellip;
CVE-2026-9678 MEDIUM Patched 5.9 2026-06-17 Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-&hellip;
CVE-2026-9677 MEDIUM 4.8 2026-06-27 The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via &hellip;
CVE-2026-9676 MEDIUM Patched 4.3 2026-06-29 The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with S&hellip;
CVE-2026-9675 HIGH Patched 7.5 2026-06-17 Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket se&hellip;
CVE-2026-9668 MEDIUM 6.3 2026-08-26 With legitimate user credentials in hand, attackers can construct malicious SQL statements to bypass authentication logic and execute arbitrary database queries directly. T&hellip;
CVE-2026-9656 MEDIUM 4.3 2026-07-17 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.&hellip;
CVE-2026-9653 NONE &mdash; 2026-07-14 A denial-of-service security issue exists across all the 1756-EN2, EN3, and ENBT communication module due to improper validation of CIP Implicit Connection packets. An atta&hellip;
CVE-2026-9651 MEDIUM Patched 4.4 2026-06-25 CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise whe&hellip;
CVE-2026-9650 HIGH Patched 7.5 2026-06-25 CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses&hellip;
CVE-2026-9648 CRITICAL 9.1 2026-06-11 The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside&hellip;
CVE-2026-9643 HIGH 7.2 2026-06-24 The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, &hellip;
CVE-2026-9641 MEDIUM Patched 5.3 2026-06-12 Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default algorithm and number of iterations. The default algorithm is HMAC-SHA1, which should only be used for l&hellip;
CVE-2026-9640 HIGH Patched 7.2 2026-06-26 A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies &hellip;