Search
13,088 CVEs
CVEs (13,088, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 13,088 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86257 | MEDIUM | Patched | 5.4 | 2026-09-06 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers c… |
| CVE-2026-86256 | MEDIUM | Patched | 5.4 | 2026-09-06 | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonati… |
| CVE-2026-86255 | MEDIUM | Patched | 6.5 | 2026-09-06 | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers … |
| CVE-2026-86254 | MEDIUM | 6.8 | 2026-09-06 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer c… | |
| CVE-2026-86253 | MEDIUM | Patched | 5.9 | 2026-09-06 | h3 (npm package) versions <= 2.0.1-rc.14 contain a path traversal vulnerability in serveStatic(). On Node.js deployments, event.url.pathname is not normalized, so percent-e… |
| CVE-2026-86252 | MEDIUM | Patched | 5.3 | 2026-09-06 | h3 versions before 1.15.9 fail to sanitize carriage return characters in EventStream data and comment fields, allowing attackers to inject arbitrary SSE events by including… |
| CVE-2026-86251 | MEDIUM | Patched | 5.9 | 2026-09-06 | h3 versions before 1.15.9 contain a path traversal vulnerability in the serveStatic utility. A double-decoding flaw allows a request path containing double-encoded dot sequ… |
| CVE-2026-86250 | HIGH | Patched | 7.5 | 2026-09-06 | h3 versions before 2.0.1-rc.18 fail to validate the chunk count parsed from user-controlled cookie values in setChunkedCookie() and deleteChunkedCookie() functions. Attacke… |
| CVE-2026-8625 | MEDIUM | 6.4 | 2026-09-05 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (Custom HTML bl… | |
| CVE-2026-86245 | MEDIUM | 6.3 | 2026-09-07 | A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. … | |
| CVE-2026-86244 | MEDIUM | 4.3 | 2026-09-07 | A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php… | |
| CVE-2026-86242 | HIGH | Patched | 8.1 | 2026-09-06 | Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is d… |
| CVE-2026-86241 | MEDIUM | 4.3 | 2026-09-07 | A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component… | |
| CVE-2026-86240 | MEDIUM | 4.7 | 2026-09-07 | A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component U… | |
| CVE-2026-86239 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.ph… | |
| CVE-2026-86238 | MEDIUM | 4.3 | 2026-09-07 | A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedbac… | |
| CVE-2026-86237 | MEDIUM | 5.3 | 2026-09-07 | A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/… | |
| CVE-2026-86236 | MEDIUM | 6.3 | 2026-09-07 | A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Suc… | |
| CVE-2026-86235 | MEDIUM | 6.3 | 2026-09-07 | A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulati… | |
| CVE-2026-86234 | MEDIUM | 6.3 | 2026-09-07 | A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation o… | |
| CVE-2026-86233 | MEDIUM | 6.3 | 2026-09-07 | A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.ph… | |
| CVE-2026-86232 | MEDIUM | 6.3 | 2026-09-06 | A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?typ… | |
| CVE-2026-86231 | LOW | 3.7 | 2026-09-06 | A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performi… | |
| CVE-2026-8623 | MEDIUM | 6.4 | 2026-09-05 | The Dear Flipbook – PDF Flipbook, 3D Flipbook, PDF embed, PDF viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'post_content (class attribut… | |
| CVE-2026-86228 | MEDIUM | 4.3 | 2026-09-06 | A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-m… |