Search
158,556 CVEs · Medium severity
CVEs (158,556, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 151–175 of 158,556 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-9729 | MEDIUM | 6.4 | 2026-07-23 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par… | |
| CVE-2026-9635 | MEDIUM | 6.4 | 2026-07-23 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in… | |
| CVE-2026-9577 | MEDIUM | Patched | 4.8 | 2026-07-23 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?… |
| CVE-2026-9066 | MEDIUM | Patched | 6.1 | 2026-07-23 | The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java… |
| CVE-2026-63226 | MEDIUM | 5.8 | 2026-07-23 | Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinatio… | |
| CVE-2026-6390 | MEDIUM | 6.8 | 2026-07-23 | A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted f… | |
| CVE-2026-7120 | MEDIUM | Patched | 5.3 | 2026-07-23 | @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to an… |
| CVE-2026-21723 | MEDIUM | 5.3 | 2026-07-23 | The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a… | |
| CVE-2026-16653 | MEDIUM | 5.3 | 2026-07-23 | A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public F… | |
| CVE-2026-16631 | MEDIUM | 5.3 | 2026-07-23 | A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Hand… | |
| CVE-2026-16630 | MEDIUM | 5.3 | 2026-07-22 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The… | |
| CVE-2026-16629 | MEDIUM | 5.3 | 2026-07-22 | A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of th… | |
| CVE-2026-16628 | MEDIUM | 5.3 | 2026-07-22 | A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing… | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-13076 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation … | |
| CVE-2026-13075 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. T… | |
| CVE-2026-13074 | MEDIUM | 5.3 | 2026-07-22 | An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in e… | |
| CVE-2026-13073 | MEDIUM | 4.3 | 2026-07-22 | An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of servic… | |
| CVE-2026-13071 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue … | |
| CVE-2026-13070 | MEDIUM | 5.3 | 2026-07-22 | A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP … | |
| CVE-2026-13069 | MEDIUM | 6.5 | 2026-07-22 | An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing … | |
| CVE-2026-13068 | MEDIUM | 4.2 | 2026-07-22 | An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongo… | |
| CVE-2026-13067 | MEDIUM | 6.3 | 2026-07-22 | When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-li… | |
| CVE-2026-13066 | MEDIUM | 6.5 | 2026-07-22 | Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in… | |
| CVE-2026-13065 | MEDIUM | 6.5 | 2026-07-22 | A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the… |