Search
78,575 CVEs
CVEs (78,575, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 78,575 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9759 | MEDIUM | Patched | 5.5 | 2026-05-27 | ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service |
| CVE-2026-9758 | HIGH | 7.3 | 2026-06-10 | Improper comparison with the certificates trusted list in S2OPC allows an attacker well-formed untrusted certificate to be considered trusted | |
| CVE-2026-9757 | HIGH | 7.5 | 2026-05-30 | The GEO my WP plugin for WordPress is vulnerable to SQL Injection via the 'swlatlng' and 'nelatlng' parameters in all versions up to, and including, 4.5.5 The parameters ar… | |
| CVE-2026-9756 | MEDIUM | 6.4 | 2026-07-03 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an… | |
| CVE-2026-9754 | MEDIUM | Patched | 6.5 | 2026-06-09 | An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command |
| CVE-2026-9753 | HIGH | Patched | 8.1 | 2026-06-09 | The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash … |
| CVE-2026-9752 | MEDIUM | Patched | 6.5 | 2026-06-09 | An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a str… |
| CVE-2026-9751 | MEDIUM | Patched | 5.5 | 2026-06-09 | The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text. |
| CVE-2026-9750 | MEDIUM | Patched | 6.5 | 2026-06-09 | An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query ex… |
| CVE-2026-9749 | MEDIUM | Patched | 6.5 | 2026-06-09 | This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a … |
| CVE-2026-9748 | MEDIUM | Patched | 6.5 | 2026-06-09 | The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a g… |
| CVE-2026-9747 | MEDIUM | Patched | 6.5 | 2026-06-09 | Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server. |
| CVE-2026-9746 | MEDIUM | Patched | 6.5 | 2026-06-09 | When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special pr… |
| CVE-2026-9745 | MEDIUM | 6.5 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This om… | |
| CVE-2026-9744 | MEDIUM | 5.3 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv… | |
| CVE-2026-9743 | MEDIUM | Patched | 6.5 | 2026-06-09 | In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cu… |
| CVE-2026-9742 | HIGH | Patched | 7.5 | 2026-06-09 | When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. … |
| CVE-2026-9741 | MEDIUM | Patched | 6.5 | 2026-06-09 | A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal va… |
| CVE-2026-9740 | HIGH | Patched | 7.5 | 2026-06-09 | A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON valida… |
| CVE-2026-9739 | NONE | — | 2026-05-27 | Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP… | |
| CVE-2026-9738 | MEDIUM | 4.4 | 2026-07-11 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and… | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-9736 | MEDIUM | 5.3 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements w… | |
| CVE-2026-9735 | MEDIUM | Patched | 5.5 | 2026-06-09 | MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the… |
| CVE-2026-9734 | MEDIUM | 4.3 | 2026-07-18 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor… |