Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9254 | NONE | — | 2026-08-24 | An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and … | |
| CVE-2026-9253 | HIGH | 7.2 | 2026-07-09 | The WP Cost Estimation & Payment Forms Builder (E&P Forms) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'customerInfos' parameter in all versio… | |
| CVE-2026-9244 | NONE | — | 2026-08-21 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-9242 | MEDIUM | 5.3 | 2026-06-27 | The RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login plugin for WordPress is vulnerable to Authentication Bypass via Insufficient V… | |
| CVE-2026-9240 | MEDIUM | 4.3 | 2026-07-09 | The Colissimo Officiel : Méthodes de livraison pour WooCommerce plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on… | |
| CVE-2026-9237 | MEDIUM | 4.3 | 2026-07-09 | The Employee, Leave and Recruitment Management System – Crew HRM plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.2.2. Thi… | |
| CVE-2026-9235 | MEDIUM | 4.3 | 2026-07-09 | The DHL eCommerce (Benelux) for WooCommerce plugin for WordPress is vulnerable to unauthorized modification and loss of data due to a missing capability check and missing n… | |
| CVE-2026-9233 | MEDIUM | 4.3 | 2026-06-27 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This … | |
| CVE-2026-9230 | MEDIUM | 4.3 | 2026-07-03 | The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This … | |
| CVE-2026-9222 | HIGH | 8.1 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior only require the password hash when authenticating with backend services from the client. Thi… | |
| CVE-2026-9221 | HIGH | 7.5 | 2026-06-26 | The Setracker2 Android Companion App (com.tgelec.setracker) versions 3.1.5 and earlier uses MD5 to generate a request signature for authenticating communications between th… | |
| CVE-2026-9220 | HIGH | 7.5 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior encrypts requests between the watch and its backend with static hardcoded AES keys and initia… | |
| CVE-2026-9219 | MEDIUM | 6.5 | 2026-06-26 | Setracker2 Android Companion App com.tgelec.setracker versions 3.1.5 and prior have a predictable registration ID derived from IMEI. The enrollment system lacks additional … | |
| CVE-2026-9214 | NONE | — | 2026-08-11 | Insufficient input validation vulnerability in the NETGEAR R7000 models allows authenticated administrators connected to the local network to make unauthorized modificati… | |
| CVE-2026-9205 | HIGH | Patched | 7.4 | 2026-08-05 | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. |
| CVE-2026-9204 | MEDIUM | Patched | 5.3 | 2026-06-11 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions … |
| CVE-2026-9203 | HIGH | Patched | 8.5 | 2026-08-05 | A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protectio… |
| CVE-2026-9202 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … |
| CVE-2026-9201 | HIGH | Patched | 8.8 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mec… |
| CVE-2026-9199 | MEDIUM | 4.3 | 2026-06-18 | The Equalize Digital Accessibility Checker – WCAG, ADA, EAA and Section 508 compliance plugin for WordPress is vulnerable to authorization bypass in all versions up to, and… | |
| CVE-2026-9198 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… |
| CVE-2026-9196 | HIGH | Patched | 8.1 | 2026-08-05 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑g… |
| CVE-2026-9195 | CRITICAL | Patched | 9.3 | 2026-08-05 | A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administ… |
| CVE-2026-9193 | CRITICAL | Patched | 9.9 | 2026-08-05 | An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privi… |
| CVE-2026-9192 | CRITICAL | Patched | 9.8 | 2026-08-05 | An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass pass… |