Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-13337 | NONE | — | 2026-09-01 | CWE-564: SQL Injection: Hibernate vulnerability exists that could allow the injection of a malicious HQL query in the NetBotz database when a malicious user is logged into … | |
| CVE-2026-13348 | NONE | — | 2026-09-01 | CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could allow an attacker to gain unauthorized access to a user account by perfor… | |
| CVE-2026-13447 | CRITICAL | 9.8 | 2026-09-05 | The Mstore Api plugin for WordPress is vulnerable to Authentication Bypass via JWT Forgery in versions up to, and including, 4.20.0 This is due to missing cryptographic sig… | |
| CVE-2026-13608 | NONE | — | 2026-09-06 | A flaw in the libcurl SASL negotiation for LDAP authentication allows an incomplete handshake sequence to be misinterpreted as a successful cryptographic verification. An a… | |
| CVE-2026-13611 | MEDIUM | Patched | 5.3 | 2026-09-01 | The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient r… |
| CVE-2026-14199 | HIGH | 7.1 | 2026-09-02 | Only self-managed Grafana instances with Auth Proxy authentication and identity caching enabled (sync_ttl greater than zero) are affected. The Auth Proxy cache key concaten… | |
| CVE-2026-14215 | MEDIUM | Patched | 6.5 | 2026-09-02 | The Booking for Appointments and Events Calendar WordPress plugin before 2.4.9 does not require authentication or a valid request token before running the post-booking act… |
| CVE-2026-14255 | MEDIUM | 5.5 | 2026-09-02 | A maliciously crafted IFC file, when parsed through certain Autodesk products, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vuln… | |
| CVE-2026-14296 | HIGH | 7.5 | 2026-09-07 | When using the Direct XIP update strategy, the main application image starts other cores (i.e. radio core), based on the currently active slot without additional verificati… | |
| CVE-2026-14297 | NONE | — | 2026-09-07 | A buffer overflow in the Bluetooth Continuous Glucose Monitoring Service (CGMS) Record Access Control Point (RACP) write handler allows an authenticated BLE peer … | |
| CVE-2026-14326 | LOW | 3.8 | 2026-09-02 | The Timetics WordPress plugin through 1.0.61 does not enforce per-object ownership when updating appointments through its REST API, allowing users with its custom staff rol… | |
| CVE-2026-14350 | MEDIUM | 5.3 | 2026-09-04 | IBM Cloud Pak for Data System 11.3.0.2 through Interim Fix 001 could allow an unauthorized user to inject data into log messages due to improper neutralization of special e… | |
| CVE-2026-14357 | HIGH | 8.8 | 2026-09-02 | The DevKit Pro plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.3.0. This is due to a missing capability check and missing no… | |
| CVE-2026-14444 | HIGH | 7.5 | 2026-09-07 | The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization chec… | |
| CVE-2026-14466 | MEDIUM | 4.3 | 2026-09-04 | It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject … | |
| CVE-2026-14470 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request co… | |
| CVE-2026-14828 | HIGH | Patched | 8.8 | 2026-09-02 | Zohocorp ManageEngine Password Manager Pro versions before 13235, PAM360 versions before 8561, and Access Manager Plus versions before 4405 are vulnerable to an authenticat… |
| CVE-2026-14957 | HIGH | 7.5 | 2026-09-02 | In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL w… | |
| CVE-2026-14975 | MEDIUM | 6.5 | 2026-09-05 | The WP File Download plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.8 via the 'remoteurl' parameter. This makes it poss… | |
| CVE-2026-14982 | HIGH | 8.1 | 2026-09-02 | The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This mak… | |
| CVE-2026-15101 | MEDIUM | 6.4 | 2026-09-01 | The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu… | |
| CVE-2026-15232 | MEDIUM | Patched | 5.3 | 2026-09-02 | The MotoPress Appointment Booking WordPress plugin before 2.4.8 does not perform an authorization or ownership check when handling a user-supplied booking identifier on an … |
| CVE-2026-15247 | MEDIUM | Patched | 5.4 | 2026-09-05 | The Search Atlas SEO WordPress plugin before 2.6.24 does not perform a nonce or capability check before processing a settings update in one of its early-priority handlers,… |
| CVE-2026-15354 | CRITICAL | 9.8 | 2026-09-04 | The ACPT (Premium) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.66. This is due to missing authorization in the `sub… | |
| CVE-2026-15431 | NONE | — | 2026-09-03 | A potential security vulnerability has been identified in the HP Support Assistant for versions prior to 9.53.2.0. The vulnerability could potentially allow… |