Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 9,841 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9235 | MEDIUM | 4.3 | 2026-07-09 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing n… | |
| CVE-2026-9233 | MEDIUM | 4.3 | 2026-06-27 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This … | |
| CVE-2026-9230 | MEDIUM | 4.3 | 2026-07-03 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This … | |
| CVE-2026-9222 | HIGH | 8.1 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. Thi… | |
| CVE-2026-9221 | HIGH | 7.5 | 2026-06-26 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between th… | |
| CVE-2026-9220 | HIGH | 7.5 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initia… | |
| CVE-2026-9219 | MEDIUM | 6.5 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional … | |
| CVE-2026-9202 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … | |
| CVE-2026-9198 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… | |
| CVE-2026-9188 | MEDIUM | 5.3 | 2026-07-02 | The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and includ… | |
| CVE-2026-9184 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu… | |
| CVE-2026-9183 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block… | |
| CVE-2026-9182 | CRITICAL | Patched | 9.8 | 2026-07-06 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endp… |
| CVE-2026-9181 | CRITICAL | Patched | 9.8 | 2026-07-06 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by se… |
| CVE-2026-9180 | MEDIUM | 5.3 | 2026-07-03 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This i… | |
| CVE-2026-9179 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc… | |
| CVE-2026-9178 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/… | |
| CVE-2026-9175 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This… | |
| CVE-2026-9172 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability … | |
| CVE-2026-9171 | HIGH | 7.5 | 2026-07-17 | IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the s… | |
| CVE-2026-9165 | HIGH | 7.7 | 2026-07-06 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. A… | |
| CVE-2026-9155 | HIGH | 8.8 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter… | |
| CVE-2026-9154 | HIGH | 7.1 | 2026-06-25 | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths … | |
| CVE-2026-9153 | MEDIUM | 6.5 | 2026-06-25 | Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to in… | |
| CVE-2026-9148 | HIGH | 7.2 | 2026-07-03 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 T… |