Search
163,503 CVEs · Medium severity
CVEs (163,503, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 163,503 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9639 | MEDIUM | Patched | 6.5 | 2026-06-26 | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions … |
| CVE-2026-9635 | MEDIUM | 6.4 | 2026-07-23 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in… | |
| CVE-2026-9629 | MEDIUM | 6.4 | 2026-06-13 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input s… | |
| CVE-2026-9626 | MEDIUM | 6.4 | 2026-07-03 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and incl… | |
| CVE-2026-9620 | MEDIUM | 6.4 | 2026-06-24 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0… | |
| CVE-2026-9619 | MEDIUM | 4.3 | 2026-06-24 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not pr… | |
| CVE-2026-9618 | MEDIUM | 4.3 | 2026-05-28 | The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Fo… | |
| CVE-2026-9617 | MEDIUM | Patched | 6.8 | 2026-05-27 | PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If… |
| CVE-2026-9616 | MEDIUM | 4.3 | 2026-06-24 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve… | |
| CVE-2026-9612 | MEDIUM | 5.3 | 2026-06-24 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y… | |
| CVE-2026-9609 | MEDIUM | 4.7 | 2026-05-27 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The at… | |
| CVE-2026-9607 | MEDIUM | 6.3 | 2026-05-27 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation… | |
| CVE-2026-9604 | MEDIUM | 4.3 | 2026-05-26 | A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/… | |
| CVE-2026-9603 | MEDIUM | 6.5 | 2026-05-26 | A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The man… | |
| CVE-2026-9602 | MEDIUM | Patched | 6.5 | 2026-07-17 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to … |
| CVE-2026-9599 | MEDIUM | 4.3 | 2026-06-02 | The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce vali… | |
| CVE-2026-9597 | MEDIUM | Patched | 5.4 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, w… |
| CVE-2026-9595 | MEDIUM | Patched | 5.3 | 2026-06-15 | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it … |
| CVE-2026-9594 | MEDIUM | 4.4 | 2026-06-06 | The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location… | |
| CVE-2026-9593 | MEDIUM | 6.7 | 2026-08-03 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the app… | |
| CVE-2026-9590 | MEDIUM | Patched | 5.3 | 2026-06-02 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify… |
| CVE-2026-9583 | MEDIUM | 4.3 | 2026-05-26 | A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of t… | |
| CVE-2026-9582 | MEDIUM | 4.3 | 2026-05-26 | A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipula… | |
| CVE-2026-9581 | MEDIUM | 6.3 | 2026-05-26 | A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper acces… | |
| CVE-2026-9579 | MEDIUM | 6.3 | 2026-05-26 | A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The man… |