Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9331 | HIGH | 7.1 | 2026-09-08 | The EDD Product Catalog Feed by PixelYourSite plugin for WordPress is vulnerable to unauthorized modification of data that can lead to a denial of service due to a missing … | |
| CVE-2026-9324 | NONE | — | 2026-08-21 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-9323 | HIGH | 8.1 | 2026-07-18 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that … | |
| CVE-2026-9322 | HIGH | Patched | 7.5 | 2026-07-30 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 are vulnerable to a denial of service via a crafted H… |
| CVE-2026-9321 | NONE | — | 2026-08-21 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-9320 | MEDIUM | Patched | 5.9 | 2026-06-22 | IBM WebSphere Application Server 9.0, and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to a denial of service, caused by send… |
| CVE-2026-9318 | MEDIUM | 5.4 | 2026-08-12 | tablib prior to 3.10.0 contains a stored cross-site scripting vulnerability in the HTML export functionality that allows attackers to execute arbitrary JavaScript by embedd… | |
| CVE-2026-9317 | HIGH | Patched | 8.1 | 2026-09-04 | Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by … |
| CVE-2026-9307 | NONE | — | 2026-06-16 | A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnos… | |
| CVE-2026-9292 | NONE | — | 2026-07-14 | A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied inp… | |
| CVE-2026-9282 | HIGH | 7.5 | 2026-07-11 | The W3 Total Cache plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.9.4 via the setupSources function. This makes it possib… | |
| CVE-2026-9278 | MEDIUM | Patched | 5.4 | 2026-06-15 | The Form Builder CP WordPress plugin before 1.2.47 does not properly sanitize a form configuration value before storing it and using it as part of a client-side script exec… |
| CVE-2026-9273 | CRITICAL | 9.3 | 2026-08-05 | The Membership Plugin – Kadence Memberships plugin for WordPress (formerly Restrict Content) is vulnerable to password reset link poisoning leading to account takeover in a… | |
| CVE-2026-9272 | HIGH | Patched | 8.1 | 2026-07-02 | In Progress Flowmon ADS versions prior to 12.5.6 and 13.0.5, a vulnerability exists whereby an adversary who is authenticated as a low-privileged user in the Anomaly Detect… |
| CVE-2026-9271 | MEDIUM | 5.9 | 2026-06-12 | Vulnerability Title | |
| CVE-2026-9269 | LOW | Patched | 3.5 | 2026-06-12 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege use… |
| CVE-2026-9267 | NONE | — | 2026-06-29 | Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows … | |
| CVE-2026-9266 | NONE | — | 2026-06-12 | A Missing Required Cryptographic Step vulnerability has been identified in Moxa's embedded Linux firmware for industrial computers and controllers. This vulnerability repre… | |
| CVE-2026-9265 | CRITICAL | Patched | 9.1 | 2026-06-20 | Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OOB read in print_attribute UTF8STRING path. print_attribute() copies a UTF8STRING ASN.1 attribute valu… |
| CVE-2026-9263 | MEDIUM | Patched | 6.5 | 2026-06-30 | The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the length field of a framed ISO PDU start segment. Per t… |
| CVE-2026-9262 | MEDIUM | Patched | 6.5 | 2026-06-16 | Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9261 | MEDIUM | Patched | 6.8 | 2026-06-16 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9260 | MEDIUM | Patched | 6.2 | 2026-06-16 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9259 | MEDIUM | Patched | 6.5 | 2026-06-16 | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier |
| CVE-2026-9258 | MEDIUM | Patched | 6.5 | 2026-06-16 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier |