Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,503 CVEs · Medium severity

CVEs (163,503, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 163,503 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9639 MEDIUM Patched 6.5 2026-06-26 Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions …
CVE-2026-9635 MEDIUM 6.4 2026-07-23 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in…
CVE-2026-9629 MEDIUM 6.4 2026-06-13 The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input s…
CVE-2026-9626 MEDIUM 6.4 2026-07-03 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and incl…
CVE-2026-9620 MEDIUM 6.4 2026-06-24 The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0…
CVE-2026-9619 MEDIUM 4.3 2026-06-24 The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not pr…
CVE-2026-9618 MEDIUM 4.3 2026-05-28 The PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) plugin for WordPress is vulnerable to Cross-Site Request Fo…
CVE-2026-9617 MEDIUM Patched 6.8 2026-05-27 PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a table and placing malicious code inside a column identifier. If…
CVE-2026-9616 MEDIUM 4.3 2026-06-24 The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve…
CVE-2026-9612 MEDIUM 5.3 2026-06-24 The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y…
CVE-2026-9609 MEDIUM 4.7 2026-05-27 A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The at…
CVE-2026-9607 MEDIUM 6.3 2026-05-27 A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation…
CVE-2026-9604 MEDIUM 4.3 2026-05-26 A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/…
CVE-2026-9603 MEDIUM 6.5 2026-05-26 A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The man…
CVE-2026-9602 MEDIUM Patched 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to &hellip;
CVE-2026-9599 MEDIUM 4.3 2026-06-02 The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce vali&hellip;
CVE-2026-9597 MEDIUM Patched 5.4 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, w&hellip;
CVE-2026-9595 MEDIUM Patched 5.3 2026-06-15 Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it &hellip;
CVE-2026-9594 MEDIUM 4.4 2026-06-06 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location&hellip;
CVE-2026-9593 MEDIUM 6.7 2026-08-03 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the app&hellip;
CVE-2026-9590 MEDIUM Patched 5.3 2026-06-02 Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify&hellip;
CVE-2026-9583 MEDIUM 4.3 2026-05-26 A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of t&hellip;
CVE-2026-9582 MEDIUM 4.3 2026-05-26 A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipula&hellip;
CVE-2026-9581 MEDIUM 6.3 2026-05-26 A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper acces&hellip;
CVE-2026-9579 MEDIUM 6.3 2026-05-26 A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The man&hellip;