Search
133,513 CVEs · High severity
CVEs (133,513, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 133,513 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9710 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to ever… |
| CVE-2026-9709 | HIGH | Patched | 7.7 | 2026-06-24 | The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of … |
| CVE-2026-9702 | HIGH | Patched | 7.5 | 2026-06-25 | The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destin… |
| CVE-2026-9700 | HIGH | 7.5 | 2026-07-08 | The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping… | |
| CVE-2026-9697 | HIGH | Patched | 7.4 | 2026-06-17 | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SO… |
| CVE-2026-9690 | HIGH | 7.5 | 2026-06-17 | Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions. | |
| CVE-2026-9675 | HIGH | Patched | 7.5 | 2026-06-17 | Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket se… |
| CVE-2026-9662 | HIGH | 8.1 | 2026-06-09 | The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validatio… | |
| CVE-2026-9658 | HIGH | Patched | 7.3 | 2026-05-28 | Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking… |
| CVE-2026-9650 | HIGH | Patched | 7.5 | 2026-06-25 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses… |
| CVE-2026-9643 | HIGH | 7.2 | 2026-06-24 | The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, … | |
| CVE-2026-9640 | HIGH | Patched | 7.2 | 2026-06-26 | A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies … |
| CVE-2026-9638 | HIGH | Patched | 7.5 | 2026-06-12 | Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitab… |
| CVE-2026-9632 | HIGH | 8.8 | 2026-05-27 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web … | |
| CVE-2026-9631 | HIGH | 8.8 | 2026-05-27 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectio… | |
| CVE-2026-9628 | HIGH | 8.8 | 2026-05-27 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Managem… | |
| CVE-2026-9627 | HIGH | 8.8 | 2026-05-27 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management I… | |
| CVE-2026-9614 | HIGH | 8.8 | 2026-06-01 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access. | |
| CVE-2026-9606 | HIGH | 7.3 | 2026-05-27 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argumen… | |
| CVE-2026-9605 | HIGH | 7.3 | 2026-05-27 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation c… | |
| CVE-2026-9584 | HIGH | 7.3 | 2026-05-26 | A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The m… | |
| CVE-2026-9580 | HIGH | 7.3 | 2026-05-26 | A vulnerability was determined in JeecgBoot up to 3.9.1. The affected element is the function LoginController.selectDepart of the file /sys/selectDepart. This manipulation … | |
| CVE-2026-9575 | HIGH | 7.3 | 2026-05-26 | A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.p… | |
| CVE-2026-9574 | HIGH | 7.3 | 2026-05-26 | A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Execut… | |
| CVE-2026-9573 | HIGH | 7.3 | 2026-05-26 | A vulnerability was detected in itsourcecode Student Transcript Processing System 1.0. This affects an unknown part of the file /admin/modules/student/index.php?view=view. … |