Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

140,640 CVEs · High severity

CVEs (140,640, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 140,640 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9753 HIGH Patched 8.1 2026-06-09 The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash …
CVE-2026-9742 HIGH Patched 7.5 2026-06-09 When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. …
CVE-2026-9740 HIGH Patched 7.5 2026-06-09 A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON valida…
CVE-2026-9717 HIGH Patched 7.2 2026-06-25 CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with eleva…
CVE-2026-9716 HIGH Patched 7.5 2026-06-25 CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable…
CVE-2026-9713 HIGH 7.5 2026-07-23 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed…
CVE-2026-9710 HIGH Patched 7.7 2026-06-24 The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to ever…
CVE-2026-9709 HIGH Patched 7.7 2026-06-24 The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of …
CVE-2026-9702 HIGH Patched 7.5 2026-06-25 The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destin…
CVE-2026-9700 HIGH 7.5 2026-07-08 The Eventer plugin for WordPress is vulnerable to time-based SQL Injection via the ‘code’ parameter in all versions up to, and including, 4.4.2 due to insufficient escaping…
CVE-2026-9697 HIGH Patched 7.4 2026-06-17 Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SO…
CVE-2026-9690 HIGH 7.5 2026-06-17 Unauthenticated Arbitrary File Download in WP Media folder Addon <= 4.0.1 versions.
CVE-2026-9675 HIGH Patched 7.5 2026-06-17 Impact: The undici WebSocket client enforces maxPayloadSize per-frame but does not enforce the cumulative size of fragmented uncompressed messages. A malicious WebSocket se&hellip;
CVE-2026-9662 HIGH 8.1 2026-06-09 The Recover Exit For WooCommerce plugin for WordPress is vulnerable to Local File Inclusion in all versions up to and including 1.0.3. This is due to insufficient validatio&hellip;
CVE-2026-9658 HIGH Patched 7.3 2026-05-28 Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking&hellip;
CVE-2026-9650 HIGH Patched 7.5 2026-06-25 CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses&hellip;
CVE-2026-9643 HIGH 7.2 2026-06-24 The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, &hellip;
CVE-2026-9640 HIGH Patched 7.2 2026-06-26 A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies &hellip;
CVE-2026-9638 HIGH Patched 7.5 2026-06-12 Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitab&hellip;
CVE-2026-9632 HIGH 8.8 2026-05-27 A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of the component Web &hellip;
CVE-2026-9631 HIGH 8.8 2026-05-27 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectio&hellip;
CVE-2026-9628 HIGH 8.8 2026-05-27 A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Managem&hellip;
CVE-2026-9627 HIGH 8.8 2026-05-27 A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management I&hellip;
CVE-2026-9614 HIGH 8.8 2026-06-01 An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
CVE-2026-9606 HIGH 7.3 2026-05-27 A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argumen&hellip;