Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

9,841 CVEs

CVEs (9,841, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 9,841 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9007 NONE — 2026-07-15 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (…
CVE-2026-9002 MEDIUM Patched 6.5 2026-06-30 IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The applica…
CVE-2026-8996 MEDIUM 6.5 2026-07-09 The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the downloa…
CVE-2026-8989 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with phys…
CVE-2026-8988 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. …
CVE-2026-8987 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at…
CVE-2026-8986 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv…
CVE-2026-8985 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can su…
CVE-2026-8984 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test …
CVE-2026-8983 NONE — 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An atta…
CVE-2026-8982 NONE — 2026-07-21 Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d…
CVE-2026-8944 MEDIUM 4.3 2026-06-30 The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to mi…
CVE-2026-8933 HIGH 7.8 2026-07-21 A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution en…
CVE-2026-8932 HIGH Patched 7.5 2026-07-03 libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously …
CVE-2026-8927 CRITICAL Patched 9.1 2026-07-03 When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between req…
CVE-2026-8926 CRITICAL Patched 9.1 2026-07-03 When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, cur…
CVE-2026-8925 CRITICAL Patched 9.8 2026-07-03 The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same p…
CVE-2026-8924 CRITICAL Patched 9.1 2026-07-03 A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled or…
CVE-2026-8921 NONE Patched — 2026-07-03 External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message…
CVE-2026-8920 NONE — 2026-07-15 Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file o…
CVE-2026-8919 NONE — 2026-07-15 Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a cra…
CVE-2026-8905 MEDIUM 6.1 2026-06-24 The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect …
CVE-2026-8896 MEDIUM 6.4 2026-06-24 The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_tex…
CVE-2026-8892 MEDIUM 6.4 2026-07-03 The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all v…
CVE-2026-8865 MEDIUM 6.4 2026-06-24 The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and in…