Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,503 CVEs · Medium severity

CVEs (163,503, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 163,503 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86212 MEDIUM 4.3 2026-09-06 A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. T…
CVE-2026-86205 MEDIUM Patched 5.4 2026-09-06 h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pat…
CVE-2022-51008 MEDIUM Patched 5.3 2026-09-06 PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers …
CVE-2021-48007 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet…
CVE-2020-37277 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s…
CVE-2026-80439 MEDIUM Patched 4.8 2026-09-06 The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes th…
CVE-2026-80437 MEDIUM Patched 4.8 2026-09-06 The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content …
CVE-2026-19862 MEDIUM Patched 4.8 2026-09-06 The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to th…
CVE-2026-19859 MEDIUM Patched 6.5 2026-09-06 The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute a…
CVE-2026-86183 MEDIUM 5.3 2026-09-06 A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.…
CVE-2026-86182 MEDIUM 4.3 2026-09-06 A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.…
CVE-2026-86179 MEDIUM 5.3 2026-09-06 A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Ba…
CVE-2026-86172 MEDIUM 6.3 2026-09-06 A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argum…
CVE-2026-86171 MEDIUM 6.3 2026-09-06 A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the ar…
CVE-2026-85038 MEDIUM Patched 5.3 2026-09-06 The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected d…
CVE-2026-84028 MEDIUM Patched 6.8 2026-09-06 The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Co…
CVE-2026-75793 MEDIUM Patched 6.5 2026-09-06 The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to crea…
CVE-2026-13159 MEDIUM 4.3 2026-09-06 The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscri…
CVE-2026-86170 MEDIUM 6.3 2026-09-06 A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argum…
CVE-2026-86164 MEDIUM 6.3 2026-09-06 A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of t…
CVE-2026-86163 MEDIUM 6.3 2026-09-06 A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argu…
CVE-2026-86150 MEDIUM 4.1 2026-09-05 A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument …
CVE-2026-6554 MEDIUM 5.5 2026-09-05 libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loo…
CVE-2026-6244 MEDIUM 5.5 2026-09-05 libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filte…
CVE-2026-31912 MEDIUM 5.5 2026-09-05 libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset th…