Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,702 CVEs · Medium severity

CVEs (3,702, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 151–175 of 3,702 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86232 MEDIUM 6.3 2026-09-06 A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?typ…
CVE-2026-86228 MEDIUM 4.3 2026-09-06 A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-m…
CVE-2026-83534 MEDIUM Patched 6.4 2026-09-06 PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser priv…
CVE-2026-19634 MEDIUM Patched 6.4 2026-09-06 PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names.…
CVE-2026-86217 MEDIUM 5.3 2026-09-06 A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component …
CVE-2026-86216 MEDIUM 4.3 2026-09-06 A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The mani…
CVE-2026-86215 MEDIUM 4.3 2026-09-06 A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout H…
CVE-2026-86258 MEDIUM 5.9 2026-09-06 nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attacker…
CVE-2026-86257 MEDIUM Patched 5.4 2026-09-06 wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers c…
CVE-2026-86256 MEDIUM Patched 5.4 2026-09-06 wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonati&hellip;
CVE-2026-86255 MEDIUM Patched 6.5 2026-09-06 wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers &hellip;
CVE-2026-86254 MEDIUM 6.8 2026-09-06 wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer c&hellip;
CVE-2026-86253 MEDIUM Patched 5.9 2026-09-06 h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-e&hellip;
CVE-2026-86252 MEDIUM Patched 5.3 2026-09-06 h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including&hellip;
CVE-2026-86251 MEDIUM Patched 5.9 2026-09-06 h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequ&hellip;
CVE-2026-86212 MEDIUM 4.3 2026-09-06 A vulnerability has been found in Open5GS 2.7.7/2.8.0. This vulnerability affects unknown code of the component AMF/MME. The manipulation leads to improper authorization. T&hellip;
CVE-2026-86205 MEDIUM Patched 5.4 2026-09-06 h3 versions before 2.0.1-rc.18 contain an open redirect vulnerability in the redirectBack() utility that fails to sanitize protocol-relative paths in the Referer header pat&hellip;
CVE-2022-51008 MEDIUM Patched 5.3 2026-09-06 PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers &hellip;
CVE-2021-48007 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet&hellip;
CVE-2020-37277 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s&hellip;
CVE-2026-80439 MEDIUM Patched 4.8 2026-09-06 The Redirection for Contact Form 7 WordPress plugin from 2.2.7 before 3.2.11 does not prevent shortcodes in submitted form values from being executed when it substitutes th&hellip;
CVE-2026-80437 MEDIUM Patched 4.8 2026-09-06 The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content &hellip;
CVE-2026-19862 MEDIUM Patched 4.8 2026-09-06 The JetFormBuilder WordPress plugin before 3.6.5.2 does not validate or strip line breaks from address values it sources from submitted form fields before adding them to th&hellip;
CVE-2026-19859 MEDIUM Patched 6.5 2026-09-06 The JetFormBuilder WordPress plugin before 3.6.5.2 does not sanitize a request parameter before rendering it as message content, allowing unauthenticated users to execute a&hellip;
CVE-2026-86183 MEDIUM 5.3 2026-09-06 A vulnerability was identified in diem-project diem up to 5.1.3. This vulnerability affects unknown code of the file dmFrontPlugin/modules/dmWidget/lib/BasedmWidgetActions.&hellip;