Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9639 | MEDIUM | Patched | 6.5 | 2026-06-26 | Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions … |
| CVE-2026-9638 | HIGH | Patched | 7.5 | 2026-06-12 | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitab… |
| CVE-2026-9637 | NONE | — | 2026-09-01 | A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length durin… | |
| CVE-2026-9636 | NONE | — | 2026-07-14 | A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security i… | |
| CVE-2026-9635 | MEDIUM | 6.4 | 2026-07-23 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in… | |
| CVE-2026-9634 | NONE | — | 2026-09-01 | A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or … | |
| CVE-2026-9633 | NONE | — | 2026-09-01 | A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or… | |
| CVE-2026-9629 | MEDIUM | 6.4 | 2026-06-13 | The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input s… | |
| CVE-2026-9626 | MEDIUM | 6.4 | 2026-07-03 | The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and incl… | |
| CVE-2026-9625 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to c… | |
| CVE-2026-9624 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length valida… | |
| CVE-2026-9622 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, r… | |
| CVE-2026-9621 | NONE | — | 2026-09-01 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the … | |
| CVE-2026-9620 | MEDIUM | 6.4 | 2026-06-24 | The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0… | |
| CVE-2026-9619 | MEDIUM | 4.3 | 2026-06-24 | The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not pr… | |
| CVE-2026-9616 | MEDIUM | 4.3 | 2026-06-24 | The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve… | |
| CVE-2026-9612 | MEDIUM | 5.3 | 2026-06-24 | The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y… | |
| CVE-2026-9611 | NONE | — | 2026-07-31 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be… | |
| CVE-2026-9610 | LOW | 2.3 | 2026-06-22 | IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by di… | |
| CVE-2026-9602 | MEDIUM | Patched | 6.5 | 2026-07-17 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to … |
| CVE-2026-9597 | MEDIUM | Patched | 5.4 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, w… |
| CVE-2026-9595 | MEDIUM | Patched | 5.3 | 2026-06-15 | Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it … |
| CVE-2026-9593 | MEDIUM | 6.7 | 2026-08-03 | A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the app… | |
| CVE-2026-9592 | NONE | — | 2026-07-17 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is … | |
| CVE-2026-9591 | NONE | — | 2026-06-17 | Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news item… |