Search
2,372 CVEs
CVEs (2,372, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 2,372 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-18480 | HIGH | Patched | 8.8 | 2026-09-06 | The SureCart WordPress plugin before 4.6.3 does not ensure that the account affected by a customer update is the same account its permission check authorised, allowing use… |
| CVE-2026-18486 | HIGH | 8.8 | 2026-09-04 | IBM ContextForge MCP Gateway <= v1.0.7 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive credentials and escalate privileges due to improper… | |
| CVE-2026-18488 | MEDIUM | 6.4 | 2026-09-01 | The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and incl… | |
| CVE-2026-18489 | HIGH | 7.4 | 2026-09-04 | IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context Forge could allow a remote attacker to obtain sensitive information from other sessions due to exposur… | |
| CVE-2026-18540 | LOW | Patched | 3.7 | 2026-09-04 | undici's retry interceptor can append the body of a ranged retry response to bytes already delivered from an earlier partial response while still presenting the original re… |
| CVE-2026-18550 | CRITICAL | 9.8 | 2026-09-01 | The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to i… | |
| CVE-2026-18567 | MEDIUM | 4.4 | 2026-09-04 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world… | |
| CVE-2026-18630 | HIGH | 8.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Managemen… | |
| CVE-2026-18658 | CRITICAL | 9.8 | 2026-09-04 | IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execut… | |
| CVE-2026-18672 | HIGH | 7.5 | 2026-09-02 | In Progress® Telerik® UI for AJAX prior to v2026.3.812, insufficient validation of client-supplied state in RadImageEditor may allow an attacker to influence which file is … | |
| CVE-2026-18730 | NONE | Patched | — | 2026-09-01 | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause the Manage API to send craft… |
| CVE-2026-18743 | LOW | 2.5 | 2026-09-01 | A flaw was found in popt. This vulnerability allows an attacker to provide specially crafted configuration content to a host, which, when loaded, can lead to a small memory… | |
| CVE-2026-18745 | NONE | — | 2026-09-04 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-18752 | MEDIUM | 6.5 | 2026-09-01 | The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient… | |
| CVE-2026-18765 | CRITICAL | 9.8 | 2026-09-01 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This … | |
| CVE-2026-18771 | HIGH | 7.5 | 2026-09-01 | Missing authentication for critical function vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Authentication Bypass.… | |
| CVE-2026-18780 | HIGH | 7.1 | 2026-09-01 | Cross-Site request forgery (CSRF) vulnerability in TMT Machine Industry and Trade Ltd. Co. Talassoft Industrial Management Software allows Cross Site Request Forgery. This… | |
| CVE-2026-18796 | NONE | — | 2026-09-07 | Any application that uses external QSPI flash for encrypted XIP on nRF5340 and relies on that encryption for confidentiality and/or integrity of the externally st… | |
| CVE-2026-18808 | CRITICAL | 9.8 | 2026-09-01 | Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This i… | |
| CVE-2026-18843 | MEDIUM | 6.1 | 2026-09-05 | The Beaver Builder Plugin (Starter Version) plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'no_results_message' node_preview Parameter in all vers… | |
| CVE-2026-18851 | HIGH | 8.8 | 2026-09-08 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges… | |
| CVE-2026-18858 | LOW | 3.3 | 2026-09-04 | IBM i 7.6, and 7.5 could allow a local authenticated attacker to obtain information from a privileged file when using SSH. | |
| CVE-2026-18887 | MEDIUM | 6.5 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access informati… | |
| CVE-2026-18905 | HIGH | 7.7 | 2026-09-04 | IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a D… | |
| CVE-2026-18922 | CRITICAL | 9.8 | 2026-09-07 | A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can… |