Search
29,760 CVEs · Medium severity
CVEs (29,760, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 176–200 of 29,760 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-86182 | MEDIUM | 4.3 | 2026-09-06 | A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.… | |
| CVE-2026-86179 | MEDIUM | 5.3 | 2026-09-06 | A flaw has been found in code-projects Daily Expense Manager 1.0. Affected is an unknown function of the file /Daily-Expense-Manager/exp_ak.sql of the component Database Ba… | |
| CVE-2026-86172 | MEDIUM | 6.3 | 2026-09-06 | A vulnerability was detected in DefaultFuction CRM 1.0.0. This impacts an unknown function of the file /modules/customers/delete.php. Performing a manipulation of the argum… | |
| CVE-2026-86171 | MEDIUM | 6.3 | 2026-09-06 | A security vulnerability has been detected in DefaultFuction CRM 1.0.0. This affects an unknown function of the file /modules/orders/delete.php. Such manipulation of the ar… | |
| CVE-2026-85038 | MEDIUM | Patched | 5.3 | 2026-09-06 | The B2BKing — Ultimate WooCommerce B2B and Wholesale Plugin — Wholesale Prices, Bulk Order Form & More WordPress plugin before 5.2.40 does not verify that a role selected d… |
| CVE-2026-84028 | MEDIUM | Patched | 6.8 | 2026-09-06 | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Co… |
| CVE-2026-75793 | MEDIUM | Patched | 6.5 | 2026-09-06 | The SureCart WordPress plugin before 4.7.0 does not consult the site's user registration setting before creating WordPress accounts, allowing unauthenticated users to crea… |
| CVE-2026-13159 | MEDIUM | 4.3 | 2026-09-06 | The Real Estate Papi WordPress theme through 1.0.5 does not perform capability or CSRF checks on one of its AJAX actions, allowing any authenticated user, such as a subscri… | |
| CVE-2026-86170 | MEDIUM | 6.3 | 2026-09-06 | A weakness has been identified in DefaultFuction CRM 1.0.0. The impacted element is an unknown function of the file /modules/orders/edit.php. This manipulation of the argum… | |
| CVE-2026-86164 | MEDIUM | 6.3 | 2026-09-06 | A security flaw has been discovered in itsourcecode Sales and Inventory System 1.0. Affected is an unknown function of the file /pages/trans_view.php. The manipulation of t… | |
| CVE-2026-86163 | MEDIUM | 6.3 | 2026-09-06 | A vulnerability was identified in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/pro_del.php. The manipulation of the argu… | |
| CVE-2026-86150 | MEDIUM | 4.1 | 2026-09-05 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument … | |
| CVE-2026-6554 | MEDIUM | 5.5 | 2026-09-05 | libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loo… | |
| CVE-2026-6244 | MEDIUM | 5.5 | 2026-09-05 | libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filte… | |
| CVE-2026-31912 | MEDIUM | 5.5 | 2026-09-05 | libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset th… | |
| CVE-2026-31911 | MEDIUM | 5.5 | 2026-09-05 | libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminat… | |
| CVE-2026-18313 | MEDIUM | 4.3 | 2026-09-05 | rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it l… | |
| CVE-2026-18238 | MEDIUM | 5.0 | 2026-09-05 | The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message a… | |
| CVE-2026-86192 | MEDIUM | 6.5 | 2026-09-05 | SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues… | |
| CVE-2026-86191 | MEDIUM | 4.3 | 2026-09-05 | SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attr… | |
| CVE-2026-86187 | MEDIUM | 5.9 | 2026-09-05 | WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to pass… | |
| CVE-2026-86186 | MEDIUM | 6.5 | 2026-09-05 | AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force p… | |
| CVE-2026-15550 | MEDIUM | 4.3 | 2026-09-05 | The Ninja Forms - Save Progress plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 3.0.30. This is due to the lack of capability … | |
| CVE-2026-12843 | MEDIUM | 5.4 | 2026-09-05 | The LearnDash LMS plugin for WordPress is vulnerable to authorization bypass in versions 4.25.0 - 5.1.6. This is due to the plugin not properly verifying that a user is aut… | |
| CVE-2025-15647 | MEDIUM | Patched | 5.5 | 2026-09-05 | CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round… |