Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9639 MEDIUM Patched 6.5 2026-06-26 Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions …
CVE-2026-9638 HIGH Patched 7.5 2026-06-12 Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitab…
CVE-2026-9637 NONE — 2026-09-01 A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length durin…
CVE-2026-9636 NONE — 2026-07-14 A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security i…
CVE-2026-9635 MEDIUM 6.4 2026-07-23 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in…
CVE-2026-9634 NONE — 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or …
CVE-2026-9633 NONE — 2026-09-01 A security issue exists within the Redundancy Module Configuration Tool. The RM3ConfigTool.exe binary searches directories in the system path for a required DLL, and one or…
CVE-2026-9629 MEDIUM 6.4 2026-06-13 The Canvas plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'tag' parameter in all versions up to, and including, 2.5.2 due to insufficient input s…
CVE-2026-9626 MEDIUM 6.4 2026-07-03 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and incl…
CVE-2026-9625 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to c…
CVE-2026-9624 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length valida…
CVE-2026-9622 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, r…
CVE-2026-9621 NONE — 2026-09-01 A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the …
CVE-2026-9620 MEDIUM 6.4 2026-06-24 The WP Latest Posts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via crafted image src attributes in post content in versions up to, and including, 5.0…
CVE-2026-9619 MEDIUM 4.3 2026-06-24 The Reviews and Rating – Docplanner plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.1.4. This is due to the plugin not pr…
CVE-2026-9616 MEDIUM 4.3 2026-06-24 The Generate Security.txt plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.12. This is due to the plugin not properly ve…
CVE-2026-9612 MEDIUM 5.3 2026-06-24 The WhatsOrder – Instant Checkout for WooCommerce plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.0.1 via the y…
CVE-2026-9611 NONE — 2026-07-31 Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be…
CVE-2026-9610 LOW 2.3 2026-06-22 IBM Datacap 9.1.7, 9.1.8, and 9.1.9 and IBM Datacap Navigator 9.1.7, 9.1.8, and 9.1.9 exposes resources or functionality that isn't linked in the UI but is accessible by di…
CVE-2026-9602 MEDIUM Patched 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to &hellip;
CVE-2026-9597 MEDIUM Patched 5.4 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4 fail to verify whether a guest account is deactivated before creating a session in the magic-link token login path, w&hellip;
CVE-2026-9595 MEDIUM Patched 5.3 2026-06-15 Impact: When a user-configured proxy on webpack-dev-server has a broad context (e.g. /) and ws: true, it also intercepts the dev server's own HMR WebSocket and forwards it &hellip;
CVE-2026-9593 MEDIUM 6.7 2026-08-03 A vulnerability in the iDTM FDI allows an attacker with elevated privileges and access to the host system to enable the debug interface by placing a crafted file in the app&hellip;
CVE-2026-9592 NONE &mdash; 2026-07-17 SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is &hellip;
CVE-2026-9591 NONE &mdash; 2026-06-17 Cross-site request forgery (CSRF) in NewsItemApiController in SimplCommerce prior to commit 6233d73e allows an unauthenticated remote attacker to create or modify news item&hellip;