Search
163,528 CVEs · Medium severity
CVEs (163,528, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 76–100 of 163,528 (capped at 500)
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86307 | MEDIUM | 4.3 | 2026-09-07 | A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects un… | |
| CVE-2026-78487 | MEDIUM | 5.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Use of Hard-coded Cryptographic Key vulnerability… | |
| CVE-2026-79734 | MEDIUM | 5.9 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Certificate Validation vulnerability. An… | |
| CVE-2026-80128 | MEDIUM | 6.4 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Authentication vulnerability. A low priv… | |
| CVE-2026-80129 | MEDIUM | 6.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Limitation of a Pathname to a Restricted… | |
| CVE-2026-12757 | MEDIUM | 6.5 | 2026-09-07 | The The Email Subscribers & Newsletters – Email Marketing, Post Notifications & Newsletter Plugin for WordPress plugin for WordPress is vulnerable to arbitrary shortcode ex… | |
| CVE-2026-8279 | MEDIUM | 5.3 | 2026-09-07 | The Masteriyo LMS plugin for WordPress is vulnerable to unauthorized data deletion due to a missing capability check on the 'delete_item_permissions_check' function in the … | |
| CVE-2026-86432 | MEDIUM | Patched | 5.3 | 2026-09-07 | commonmark versions from 2.0.0 before 2.8.4 contain a denial of service vulnerability in XmlRenderer that emits depth-proportional indentation for every XML tag. Attackers … |
| CVE-2026-86416 | MEDIUM | Patched | 5.4 | 2026-09-07 | ILIAS versions before 9.23, 10.11, and 11.4 contain an authorization bypass vulnerability in ilObjGroupGUI where saveMapSettingsObject() and updateGroupTypeObject() perform… |
| CVE-2026-80178 | MEDIUM | 5.5 | 2026-09-07 | Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Improper Privilege Management vulnerability. A lo… | |
| CVE-2026-86302 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was found in code-projects Hospital Information System 1.0. Affected by this vulnerability is an unknown functionality of the file /HIS/his.sql of the compo… | |
| CVE-2026-4945 | MEDIUM | 5.3 | 2026-09-07 | The Otter Blocks – Gutenberg Blocks, Page Builder for Gutenberg Editor & FSE plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, a… | |
| CVE-2026-12853 | MEDIUM | 5.4 | 2026-09-07 | The Flamingo plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.6.2. This is due to the plugin not properly verifying that a… | |
| CVE-2022-51012 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte… |
| CVE-2022-51013 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran… |
| CVE-2022-51014 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s… |
| CVE-2022-51015 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In… |
| CVE-2022-51016 | MEDIUM | Patched | 6.1 | 2026-09-07 | PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key c… |
| CVE-2022-51018 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create… |
| CVE-2022-51011 | MEDIUM | Patched | 4.3 | 2026-09-07 | PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large … |
| CVE-2022-51010 | MEDIUM | Patched | 6.5 | 2026-09-07 | PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra… |
| CVE-2026-2390 | MEDIUM | 6.4 | 2026-09-07 | The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Lazy Load module's image processing in all versions up to, and including, 3.0.4. This… | |
| CVE-2026-86294 | MEDIUM | 4.3 | 2026-09-07 | A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of th… | |
| CVE-2026-85640 | MEDIUM | 6.3 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| CVE-2026-77699 | MEDIUM | 5.0 | 2026-09-07 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. |