Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

2,372 CVEs

CVEs (2,372, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 2,372 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-18480 HIGH Patched 8.8 2026-09-06 The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use…
CVE-2026-18486 HIGH 8.8 2026-09-04 IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper&hellip;
CVE-2026-18488 MEDIUM 6.4 2026-09-01 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and incl&hellip;
CVE-2026-18489 HIGH 7.4 2026-09-04 IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposur&hellip;
CVE-2026-18540 LOW Patched 3.7 2026-09-04 undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original re&hellip;
CVE-2026-18550 CRITICAL 9.8 2026-09-01 The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i&hellip;
CVE-2026-18567 MEDIUM 4.4 2026-09-04 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world&hellip;
CVE-2026-18630 HIGH 8.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Managemen&hellip;
CVE-2026-18658 CRITICAL 9.8 2026-09-04 IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execut&hellip;
CVE-2026-18672 HIGH 7.5 2026-09-02 In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is &hellip;
CVE-2026-18730 NONE Patched &mdash; 2026-09-01 A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send craft&hellip;
CVE-2026-18743 LOW 2.5 2026-09-01 A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory&hellip;
CVE-2026-18745 NONE &mdash; 2026-09-04 Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-18752 MEDIUM 6.5 2026-09-01 The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient&hellip;
CVE-2026-18765 CRITICAL 9.8 2026-09-01 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This &hellip;
CVE-2026-18771 HIGH 7.5 2026-09-01 Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass.&hellip;
CVE-2026-18780 HIGH 7.1 2026-09-01 Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This&hellip;
CVE-2026-18796 NONE &mdash; 2026-09-07 Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally st&hellip;
CVE-2026-18808 CRITICAL 9.8 2026-09-01 Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i&hellip;
CVE-2026-18843 MEDIUM 6.1 2026-09-05 The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all vers&hellip;
CVE-2026-18851 HIGH 8.8 2026-09-08 Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges&hellip;
CVE-2026-18858 LOW 3.3 2026-09-04 IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH.
CVE-2026-18887 MEDIUM 6.5 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access informati&hellip;
CVE-2026-18905 HIGH 7.7 2026-09-04 IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a D&hellip;
CVE-2026-18922 CRITICAL 9.8 2026-09-07 A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can&hellip;