Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

158,556 CVEs · Medium severity

CVEs (158,556, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 158,556 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9609 MEDIUM 4.7 2026-05-27 A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The at…
CVE-2026-9607 MEDIUM 6.3 2026-05-27 A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation…
CVE-2026-9604 MEDIUM 4.3 2026-05-26 A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/…
CVE-2026-9603 MEDIUM 6.5 2026-05-26 A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The man…
CVE-2026-9602 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to &hellip;
CVE-2026-9599 MEDIUM 4.3 2026-06-02 The Tectite Forms plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3. This is due to missing or incorrect nonce vali&hellip;
CVE-2026-9597 MEDIUM Patched 5.4 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, w&hellip;
CVE-2026-9595 MEDIUM Patched 5.3 2026-06-15 Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it &hellip;
CVE-2026-9594 MEDIUM 4.4 2026-06-06 The WP Maps – Google Maps,OpenStreetMap,Mapbox,Store Locator,Listing,Directory & Filters plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'location&hellip;
CVE-2026-9590 MEDIUM Patched 5.3 2026-06-02 Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify&hellip;
CVE-2026-9583 MEDIUM 4.3 2026-05-26 A weakness has been identified in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This impacts an unknown function of the file /index.php of t&hellip;
CVE-2026-9582 MEDIUM 4.3 2026-05-26 A security flaw has been discovered in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects an unknown function. Performing a manipula&hellip;
CVE-2026-9581 MEDIUM 6.3 2026-05-26 A vulnerability was identified in JeecgBoot up to 3.9.1. The impacted element is an unknown function of the file /sys/comment/add. Such manipulation leads to improper acces&hellip;
CVE-2026-9579 MEDIUM 6.3 2026-05-26 A vulnerability was found in JeecgBoot up to 3.9.1. Impacted is the function user.getUsername of the file /sys/user/login/setting/userEdit of the component SysUser. The man&hellip;
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?&hellip;
CVE-2026-9576 MEDIUM Patched 4.9 2026-06-30 The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users&hellip;
CVE-2026-9571 MEDIUM Patched 5.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivat&hellip;
CVE-2026-9568 MEDIUM 5.0 2026-05-26 A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the&hellip;
CVE-2026-9566 MEDIUM 4.3 2026-05-26 A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the com&hellip;
CVE-2026-9565 MEDIUM 6.3 2026-05-26 A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the&hellip;
CVE-2026-9557 MEDIUM 6.4 2026-05-29 A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigg&hellip;
CVE-2026-9549 MEDIUM 4.8 2026-06-08 Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can c&hellip;
CVE-2026-9542 MEDIUM 6.3 2026-05-26 A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulat&hellip;
CVE-2026-9541 MEDIUM Patched 5.3 2026-05-26 A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Perform&hellip;
CVE-2026-9540 MEDIUM 5.3 2026-05-26 A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation le&hellip;