Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

158,556 CVEs · Medium severity

CVEs (158,556, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 158,556 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9729 MEDIUM 6.4 2026-07-23 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par…
CVE-2026-9635 MEDIUM 6.4 2026-07-23 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in…
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?…
CVE-2026-9066 MEDIUM Patched 6.1 2026-07-23 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java…
CVE-2026-63226 MEDIUM 5.8 2026-07-23 Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port forwarding, allowing to connect to arbitrary destinatio…
CVE-2026-6390 MEDIUM 6.8 2026-07-23 A flaw was found in GNU nano's multi-buffer error message handling. When a user opens multiple files at startup and one triggers an ALERT-level error, a specially crafted f…
CVE-2026-7120 MEDIUM Patched 5.3 2026-07-23 @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to an…
CVE-2026-21723 MEDIUM 5.3 2026-07-23 The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates with no memory limits. Mass-executing templates in a…
CVE-2026-16653 MEDIUM 5.3 2026-07-23 A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the file lib/facil/http/http.c of the component Public F…
CVE-2026-16631 MEDIUM 5.3 2026-07-23 A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/pack.js of the component package-manager Command Hand…
CVE-2026-16630 MEDIUM 5.3 2026-07-22 A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The…
CVE-2026-16629 MEDIUM 5.3 2026-07-22 A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the file source/platforms/git/localGetFileAtSHA.ts of th…
CVE-2026-16628 MEDIUM 5.3 2026-07-22 A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec of the component JIT Plugin Entry Handler. Performing…
CVE-2026-9737 MEDIUM 6.5 2026-07-22 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran…
CVE-2026-13076 MEDIUM 6.5 2026-07-22 An authenticated user can cause a {{mongod}} process to be terminated by the operating system under memory pressure by performing a specific data type conversion operation …
CVE-2026-13075 MEDIUM 6.5 2026-07-22 An authenticated user can cause the mongod process to be terminated by the operating system under memory pressure via the $rankFusion and $scoreFusion aggregation stages. T…
CVE-2026-13074 MEDIUM 5.3 2026-07-22 An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combination of parameters to the awaitable hello command in e…
CVE-2026-13073 MEDIUM 4.3 2026-07-22 An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafted aggregation command, resulting in denial of servic…
CVE-2026-13071 MEDIUM 6.5 2026-07-22 An authenticated user with read access can cause the mongod process to be terminated through certain aggregation expressions that execute server-side JavaScript. The issue …
CVE-2026-13070 MEDIUM 5.3 2026-07-22 A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP response from a remote peer during the TLS handshake. OCSP …
CVE-2026-13069 MEDIUM 6.5 2026-07-22 An authenticated user can cause excessive CPU consumption or out-of-memory conditions on a MongoDB server by sending a crafted Queryable Encryption find payload containing …
CVE-2026-13068 MEDIUM 4.2 2026-07-22 An authenticated user holding cursor termination privileges on one database may incorrectly be permitted to terminate active cursors on a separate database, disrupting ongo…
CVE-2026-13067 MEDIUM 6.3 2026-07-22 When PROXY protocol v2 is used on the Unix domain socket path, roles derived from X.509 client certificates may not be validated against the configured tlsCATrusts allow-li…
CVE-2026-13066 MEDIUM 6.5 2026-07-22 Improper handling of DBPointer objects during BSON serialization in MongoDB's server-side JavaScript engine can result in internal process memory contents being included in…
CVE-2026-13065 MEDIUM 6.5 2026-07-22 A user with read-only privileges is able to craft an aggregation pipeline using the $linearFill window function operator with a specific sortBy expression type to cause the…