Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-15550 MEDIUM 4.3 2026-09-05 The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability …
CVE-2026-15926 NONE — 2026-09-03 Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed
CVE-2026-15933 NONE Patched — 2026-09-03 OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, includ…
CVE-2026-15937 NONE &mdash; 2026-09-04 Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against&hellip;
CVE-2026-15984 HIGH 7.2 2026-09-05 The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient &hellip;
CVE-2026-16003 NONE &mdash; 2026-09-08 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IO&hellip;
CVE-2026-16004 NONE &mdash; 2026-09-08 Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL reques&hellip;
CVE-2026-16005 NONE &mdash; 2026-09-08 Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verificat&hellip;
CVE-2026-16006 NONE &mdash; 2026-09-08 Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCT&hellip;
CVE-2026-16028 NONE Patched &mdash; 2026-09-07 Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re&hellip;
CVE-2026-16180 MEDIUM 5.7 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an auth&hellip;
CVE-2026-16281 HIGH Patched 7.1 2026-09-04 The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or&hellip;
CVE-2026-16310 CRITICAL 9.8 2026-09-06 The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing vali&hellip;
CVE-2026-16502 HIGH 8.8 2026-09-08 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserializati&hellip;
CVE-2026-16647 MEDIUM Patched 4.1 2026-09-02 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versi&hellip;
CVE-2026-16649 HIGH 7.2 2026-09-05 The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficie&hellip;
CVE-2026-16660 MEDIUM 5.3 2026-09-04 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read.
CVE-2026-16675 NONE &mdash; 2026-09-01 A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol&hellip;
CVE-2026-16689 MEDIUM 6.2 2026-09-04 IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke&hellip;
CVE-2026-16693 MEDIUM 4.4 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate en&hellip;
CVE-2026-16786 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve&hellip;
CVE-2026-16787 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to&hellip;
CVE-2026-16788 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio&hellip;
CVE-2026-16826 MEDIUM 5.3 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
CVE-2026-16876 NONE &mdash; 2026-09-07 An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering&hellip;