Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-15550 | MEDIUM | 4.3 | 2026-09-05 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability … | |
| CVE-2026-15926 | NONE | — | 2026-09-03 | Rejected reason: Red Hat Product Security has determined that this CVE ID is not needed | |
| CVE-2026-15933 | NONE | Patched | — | 2026-09-03 | OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, includ… |
| CVE-2026-15937 | NONE | — | 2026-09-04 | Improper certificate validation in Checkmk <2.5.0p10 allows a relay and a push agent that share the same UUID to reuse each other's mTLS certificate to authenticate against… | |
| CVE-2026-15984 | HIGH | 7.2 | 2026-09-05 | The QuickCal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Custom Field Parameters in all versions up to, and including, 1.0.20 due to insufficient … | |
| CVE-2026-16003 | NONE | — | 2026-09-08 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to add an arbitrary process identifier to the driver's whitelist via a crafted IO… | |
| CVE-2026-16004 | NONE | — | 2026-09-08 | Exposed IOCTL with Insufficient Access Control in Armoury Crate driver allows a local user to read and write arbitrary PCI/PCIe configuration space via crafted IOCTL reques… | |
| CVE-2026-16005 | NONE | — | 2026-09-08 | Release of Invalid Pointer or Reference in Armoury Crate driver allows a local user to free arbitrary memory via a crafted IOCTL request by bypassing the driver's verificat… | |
| CVE-2026-16006 | NONE | — | 2026-09-08 | Exposure of Sensitive System Information to an Unauthorized Control Sphere in Armoury Crate driver allows a local user to obtain kernel virtual addresses via a crafted IOCT… | |
| CVE-2026-16028 | NONE | Patched | — | 2026-09-07 | Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion via closed streams that stream_state never removes from the connection stream table. When a stream re… |
| CVE-2026-16180 | MEDIUM | 5.7 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 Toolkit could allow an auth… | |
| CVE-2026-16281 | HIGH | Patched | 7.1 | 2026-09-04 | The Classified Listing WordPress plugin before 6.1.1 does not verify that the caller owns or can edit the target listing before its AI image-editing AJAX action deletes or… |
| CVE-2026-16310 | CRITICAL | 9.8 | 2026-09-06 | The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing vali… | |
| CVE-2026-16502 | HIGH | 8.8 | 2026-09-08 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.1.18 via deserializati… | |
| CVE-2026-16647 | MEDIUM | Patched | 4.1 | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versi… |
| CVE-2026-16649 | HIGH | 7.2 | 2026-09-05 | The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficie… | |
| CVE-2026-16660 | MEDIUM | 5.3 | 2026-09-04 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote attacker to cause a denial of service due to an out-of-bounds read. | |
| CVE-2026-16675 | NONE | — | 2026-09-01 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible consol… | |
| CVE-2026-16689 | MEDIUM | 6.2 | 2026-09-04 | IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 through 12.0.12.28 and IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.7 could allow a local attacke… | |
| CVE-2026-16693 | MEDIUM | 4.4 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to the use of hardcoded cryptographic constants to obfuscate en… | |
| CVE-2026-16786 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve… | |
| CVE-2026-16787 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to… | |
| CVE-2026-16788 | MEDIUM | 6.4 | 2026-09-01 | The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio… | |
| CVE-2026-16826 | MEDIUM | 5.3 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |
| CVE-2026-16876 | NONE | — | 2026-09-07 | An authentication bypass vulnerability exists in the WebGUI of Series UNIVERGE IX-R/IX-V. A user could bypass authentication and execute arbitrary CLI commands by tampering… |