Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

30,217 CVEs

CVEs (30,217, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 30,217 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9190 CRITICAL Patched 9.1 2026-08-05 An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and a…
CVE-2026-9188 MEDIUM 5.3 2026-07-02 The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and includ…
CVE-2026-9187 MEDIUM 5.3 2026-06-16 The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capa…
CVE-2026-9186 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h…
CVE-2026-9184 MEDIUM 4.3 2026-06-24 The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu…
CVE-2026-9183 MEDIUM 4.3 2026-06-24 The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block…
CVE-2026-9182 CRITICAL Patched 9.8 2026-07-06 Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endp…
CVE-2026-9181 CRITICAL Patched 9.8 2026-07-06 Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by se…
CVE-2026-9180 MEDIUM 5.3 2026-07-03 The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This i…
CVE-2026-9179 HIGH 7.5 2026-06-24 The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc…
CVE-2026-9178 HIGH 7.5 2026-06-24 The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/…
CVE-2026-9177 NONE — 2026-07-29 A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This …
CVE-2026-9175 MEDIUM 5.3 2026-06-24 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This…
CVE-2026-9172 MEDIUM 5.3 2026-06-24 The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability …
CVE-2026-9171 HIGH 7.5 2026-07-17 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote att…
CVE-2026-9169 HIGH 8.8 2026-08-07 DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by p…
CVE-2026-9165 HIGH 7.7 2026-07-06 A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. A…
CVE-2026-9162 MEDIUM Patched 4.3 2026-06-22 Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connection&hellip;
CVE-2026-9158 CRITICAL Patched 9.8 2026-06-18 In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subseq&hellip;
CVE-2026-9155 HIGH 8.8 2026-06-25 OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter&hellip;
CVE-2026-9154 HIGH 7.1 2026-06-25 Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths &hellip;
CVE-2026-9153 MEDIUM 6.5 2026-06-25 Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to in&hellip;
CVE-2026-9151 NONE Patched &mdash; 2026-06-10 An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, &hellip;
CVE-2026-9148 HIGH 7.2 2026-07-03 The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 T&hellip;
CVE-2026-9147 HIGH 7.8 2026-07-18 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f&hellip;