Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

23,172 CVEs

CVEs (23,172, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 23,172 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9746 MEDIUM Patched 6.5 2026-06-09 When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special pr…
CVE-2026-9743 MEDIUM Patched 6.5 2026-06-09 In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cu…
CVE-2026-9742 HIGH Patched 7.5 2026-06-09 When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. …
CVE-2026-9741 MEDIUM Patched 6.5 2026-06-09 A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal va…
CVE-2026-9740 HIGH Patched 7.5 2026-06-09 A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON valida…
CVE-2026-9739 NONE — 2026-05-27 Vulnerable to DNS rebinding attacks when using SSE (http://b/499408790). During the beta phase, we implemented `allowed-origins` and `allowed-hosts` flags to align with MCP…
CVE-2026-9738 MEDIUM 4.4 2026-07-11 The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and…
CVE-2026-9737 MEDIUM 6.5 2026-07-22 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran…
CVE-2026-9735 MEDIUM Patched 5.5 2026-06-09 MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the…
CVE-2026-9734 MEDIUM 4.3 2026-07-18 The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor…
CVE-2026-9733 CRITICAL 9.1 2026-06-23 Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified in the constructor, th…
CVE-2026-9732 MEDIUM 4.3 2026-06-03 The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This …
CVE-2026-9731 MEDIUM 4.3 2026-07-08 The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce val…
CVE-2026-9730 MEDIUM 4.3 2026-06-02 The Remove NoFollow Commenter URL plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing or inco…
CVE-2026-9729 MEDIUM 6.4 2026-07-23 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par…
CVE-2026-9726 CRITICAL 9.8 2026-07-10 Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in Drupal Drupal AlternativeCommerce (Basket) allows Object Injection. This iss…
CVE-2026-9725 CRITICAL 9.1 2026-07-03 The Printcart Web to Print Product Designer for WooCommerce plugin for WordPress is vulnerable to Arbitrary File Deletion in versions up to, and including, 2.5.2 This is du…
CVE-2026-9724 MEDIUM 4.3 2026-06-24 The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida…
CVE-2026-9723 MEDIUM 4.3 2026-06-02 The Google Plus One Bottom plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.0.2. This is due to missing or incorrect…
CVE-2026-9722 MEDIUM 4.3 2026-06-02 The Laiser Tag plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.5. This is due to missing or incorrect nonce valid…
CVE-2026-9721 MEDIUM 4.3 2026-06-24 The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre…
CVE-2026-9719 MEDIUM 4.3 2026-06-06 The LatePoint – Calendar Booking Plugin for Appointments and Events plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5…
CVE-2026-9718 MEDIUM Patched 6.5 2026-06-25 CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s…
CVE-2026-9717 HIGH Patched 7.2 2026-06-25 CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with eleva…
CVE-2026-9716 HIGH Patched 7.5 2026-06-25 CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable…