Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 9,841 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9007 | NONE | — | 2026-07-15 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in HCL Notes from HCL Software allows reflected Cross-Site Scripting (… | |
| CVE-2026-9002 | MEDIUM | Patched | 6.5 | 2026-06-30 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 could allow an adjacent attacker to cause a denial of service due to improper validation in the XDF decoder. The applica… |
| CVE-2026-8996 | MEDIUM | 6.5 | 2026-07-09 | The Backup and Staging by WP Time Capsule plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.22.26 via the downloa… | |
| CVE-2026-8989 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 permits unrestricted access to the NXP i.MX6 recovery mode through exposed hardware recovery pins. An attacker with phys… | |
| CVE-2026-8988 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 exposes an accessible UART interface that permits interruption of the boot process and access to the U-Boot bootloader. … | |
| CVE-2026-8987 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at… | |
| CVE-2026-8986 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv… | |
| CVE-2026-8985 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection in the /test endpoint exposed on TCP port 9002. An unauthenticated attacker can su… | |
| CVE-2026-8984 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 allows unauthenticated remote code execution via the service listening on TCP port 9002. A crafted request to the /test … | |
| CVE-2026-8983 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a hard-coded authentication token that bypasses authorization checks for multiple management endpoints. An atta… | |
| CVE-2026-8982 | NONE | — | 2026-07-21 | Two undocumented privileged accounts exist in Autel Maxi Charger Single firmware through V1.03.51. The accounts use vendor-defined password derivation mechanisms based on d… | |
| CVE-2026-8944 | MEDIUM | 4.3 | 2026-06-30 | The Plugin for Google Analytics by IO technologies plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.1. This is due to mi… | |
| CVE-2026-8933 | HIGH | 7.8 | 2026-07-21 | A local privilege escalation vulnerability exists in snap-confine, a set-capabilities core component used internally by Canonical snapd to construct the secure execution en… | |
| CVE-2026-8932 | HIGH | Patched | 7.5 | 2026-07-03 | libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously … |
| CVE-2026-8927 | CRITICAL | Patched | 9.1 | 2026-07-03 | When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between req… |
| CVE-2026-8926 | CRITICAL | Patched | 9.1 | 2026-07-03 | When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, cur… |
| CVE-2026-8925 | CRITICAL | Patched | 9.8 | 2026-07-03 | The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same p… |
| CVE-2026-8924 | CRITICAL | Patched | 9.1 | 2026-07-03 | A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled or… |
| CVE-2026-8921 | NONE | Patched | — | 2026-07-03 | External Control of File Name or Path vulnerability in ASUS Business Manager allows a local user to execute arbitrary code with SYSTEM privileges via a tampered IPC message… |
| CVE-2026-8920 | NONE | — | 2026-07-15 | Improper Restriction of Communication Channel to Intended Endpoints and External Control of File Name or Path in Aura Wallpaper Service allow a local user to perform file o… | |
| CVE-2026-8919 | NONE | — | 2026-07-15 | Permissive Cross-domain Security Policy with Untrusted Domains in ASUS GameSDK allows a remote user to obtain a local user’s NTLM hash by convincing the user to visit a cra… | |
| CVE-2026-8905 | MEDIUM | 6.1 | 2026-06-24 | The Osiris Signature Banner plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.5. This is due to missing or incorrect … | |
| CVE-2026-8896 | MEDIUM | 6.4 | 2026-06-24 | The MIR blocks and shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' attribute (and other attributes such as 'ready_animation_tex… | |
| CVE-2026-8892 | MEDIUM | 6.4 | 2026-07-03 | The CM Business Directory – Optimise and showcase local business plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Business Address Meta Fields in all v… | |
| CVE-2026-8865 | MEDIUM | 6.4 | 2026-06-24 | The Avalon23 Products Filter for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'avalon23_qr' shortcode in all versions up to, and in… |