Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?…
CVE-2026-9576 MEDIUM Patched 4.9 2026-06-30 The Fluent Booking WordPress plugin before 2.1.2 does not verify ownership of the requested group_id before exporting attendee data via the export endpoint, allowing users…
CVE-2026-9571 MEDIUM Patched 5.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to invalidate OAuth refresh tokens upon user account deactivation, which allows a deactivat&hellip;
CVE-2026-9568 MEDIUM 5.0 2026-05-26 A weakness has been identified in ThingsBoard up to 4.3.1.1. Affected by this vulnerability is the function getGatewayDockerComposeFile of the file /api/v1/provision of the&hellip;
CVE-2026-9566 MEDIUM 4.3 2026-05-26 A vulnerability was identified in teableio teable up to 1.9.x. This impacts an unknown function of the file apps/nextjs-app/src/features/auth/pages/LoginPage.tsx of the com&hellip;
CVE-2026-9565 MEDIUM 6.3 2026-05-26 A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the&hellip;
CVE-2026-9557 MEDIUM 6.4 2026-05-29 A Server-Side Request Forgery (SSRF) vulnerability exists in Mautic's Focus component. Due to insufficient validation of user-supplied URLs, an authenticated user can trigg&hellip;
CVE-2026-9549 MEDIUM 4.8 2026-06-08 Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can c&hellip;
CVE-2026-9548 MEDIUM Patched 6.5 2026-08-28 An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain in Synology Chat Server before 2.4.5-22148 allows re&hellip;
CVE-2026-9542 MEDIUM 6.3 2026-05-26 A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulat&hellip;
CVE-2026-9541 MEDIUM Patched 5.3 2026-05-26 A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File Handler. Perform&hellip;
CVE-2026-9540 MEDIUM 5.3 2026-05-26 A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation le&hellip;
CVE-2026-9539 MEDIUM 6.5 2026-06-24 An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environmen&hellip;
CVE-2026-9537 MEDIUM Patched 5.3 2026-07-17 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom&hellip;
CVE-2026-9534 MEDIUM 6.3 2026-05-26 A flaw has been found in Totolink CA750-PoE 6.2c.510. This affects the function setWiFiWpsConfig of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. Executin&hellip;
CVE-2026-9533 MEDIUM 6.3 2026-05-26 A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The impacted element is the function recvUpgradeNewFw of the file /cgi-bin/cstecgi.cgi of the component Setting&hellip;
CVE-2026-9532 MEDIUM 6.3 2026-05-26 A security vulnerability has been detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUploadUserData of the file /cgi-bin/cstecgi.cgi of the co&hellip;
CVE-2026-9531 MEDIUM 6.3 2026-05-26 A weakness has been identified in Totolink CA750-PoE 6.2c.510. Impacted is the function setUpgradeUboot of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. T&hellip;
CVE-2026-9527 MEDIUM 4.3 2026-05-26 A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of&hellip;
CVE-2026-9524 MEDIUM 6.3 2026-05-26 A flaw has been found in xianrendzw EasyReport up to 2.0.17.0522_Beta. Affected by this issue is the function execute of the component REST Endpoint. Executing a manipulati&hellip;
CVE-2026-9522 MEDIUM Patched 5.4 2026-06-02 Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to d&hellip;
CVE-2026-9520 MEDIUM 4.3 2026-05-26 A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/component&hellip;
CVE-2026-9519 MEDIUM 4.3 2026-05-26 A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of&hellip;
CVE-2026-9518 MEDIUM 4.3 2026-05-26 A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the compo&hellip;
CVE-2026-9515 MEDIUM 6.3 2026-05-26 A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Settin&hellip;