Search
30,217 CVEs
CVEs (30,217, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 201–225 of 30,217 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9190 | CRITICAL | Patched | 9.1 | 2026-08-05 | An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication and a… |
| CVE-2026-9188 | MEDIUM | 5.3 | 2026-07-02 | The Appointment Bookings for Zoom GoogleMeet and more – Wappointment plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to and includ… | |
| CVE-2026-9187 | MEDIUM | 5.3 | 2026-06-16 | The Abandoned Contact Form 7 plugin for WordPress is vulnerable to unauthorized arbitrary post deletion in versions up to, and including, 2.2. This is due to a missing capa… | |
| CVE-2026-9186 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h… | |
| CVE-2026-9184 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_lb24_token() AJAX fu… | |
| CVE-2026-9183 | MEDIUM | 4.3 | 2026-06-24 | The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block… | |
| CVE-2026-9182 | CRITICAL | Patched | 9.8 | 2026-07-06 | Esri ArcGIS Server contains an unrestricted file upload vulnerability. An unauthenticated attacker could exploit this issue by uploading a crafted file to the affected endp… |
| CVE-2026-9181 | CRITICAL | Patched | 9.8 | 2026-07-06 | Esri ArcGIS Server contains a directory traversal vulnerability. ArcGIS Enterprise on Kubernetes is not impacted. An unauthenticated attacker could exploit this issue by se… |
| CVE-2026-9180 | MEDIUM | 5.3 | 2026-07-03 | The MotoPress Appointment Booking plugin for WordPress is vulnerable to Authorization Bypass Through User-Controlled Key in all versions up to, and including, 2.4.4. This i… | |
| CVE-2026-9179 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the /wp-json/wp/v3/post/list REST endpoint in versions up to and inc… | |
| CVE-2026-9178 | HIGH | 7.5 | 2026-06-24 | The WP Forms Connector plugin for WordPress is vulnerable to Information Exposure in all versions up to, and including, 1.8. The plugin registers the REST route wp/v3/user/… | |
| CVE-2026-9177 | NONE | — | 2026-07-29 | A Server-Side Template Injection (SSTI) vulnerability was identified in the mail template functionality of the Axway SecureTransport product in version 5.5-20260326. This … | |
| CVE-2026-9175 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.2.0. This… | |
| CVE-2026-9172 | MEDIUM | 5.3 | 2026-06-24 | The Devs Accounting – Simple Accounting and Invoicing Solution plugin for WordPress is vulnerable to unauthorized modification/deletion of data due to a missing capability … | |
| CVE-2026-9171 | HIGH | 7.5 | 2026-07-17 | IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote att… | |
| CVE-2026-9169 | HIGH | 8.8 | 2026-08-07 | DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.49 on Windows allows a local attacker to execute arbitrary code with the privileges of the application by p… | |
| CVE-2026-9165 | HIGH | 7.7 | 2026-07-06 | A flaw was found in Red Hat Advanced Cluster Security for Kubernetes (RHACS). Central does not limit the depth of GraphQL queries served on the authenticated GraphQL API. A… | |
| CVE-2026-9162 | MEDIUM | Patched | 4.3 | 2026-06-22 | Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active WebSocket connection… |
| CVE-2026-9158 | CRITICAL | Patched | 9.8 | 2026-06-18 | In Eclipse 4diac FORTE versions 3.0.0 to 3.1.0, a specially crafted DELETE connection command to the management interface can lead to a dangling pointer. This allows subseq… |
| CVE-2026-9155 | HIGH | 8.8 | 2026-06-25 | OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter… | |
| CVE-2026-9154 | HIGH | 7.1 | 2026-06-25 | Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths … | |
| CVE-2026-9153 | MEDIUM | 6.5 | 2026-06-25 | Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to in… | |
| CVE-2026-9151 | NONE | Patched | — | 2026-06-10 | An OS command injection vulnerability exists in the VPN module of TP-Link Archer AX12 v1, AX17 v1. AX18 v1, and AX1300 v1.6 routers. This vulnerability allows an adjacent, … |
| CVE-2026-9148 | HIGH | 7.2 | 2026-07-03 | The Comments – wpDiscuz plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the guest commenter 'Website' field in versions up to, and including, 7.6.56 T… | |
| CVE-2026-9147 | HIGH | 7.8 | 2026-07-18 | uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f… |