Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 201–225 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86175 MEDIUM 6.5 2026-09-05 NetBox through 4.7.0 fails to redact sensitive data source backend credentials in REST and GraphQL API responses. Authenticated users with only view permission can retrieve…
CVE-2026-86176 MEDIUM 4.3 2026-09-05 NetBox through 4.7.0 fails to properly scope user-private records in REST and GraphQL API endpoints for Notifications, Subscriptions, and Bookmarks. Authenticated users wit…
CVE-2026-86178 MEDIUM 5.4 2026-09-05 Pixelfed through 0.12.9 fails to validate follower status in StoryComposeController react and comment endpoints, allowing authenticated users to access follower-only storie…
CVE-2026-86174 MEDIUM 4.3 2026-09-05 Plane through 1.4.2 fails to validate that issues belong to the deploy board's project in the public comment endpoint. Authenticated attackers can post comments to arbitrar…
CVE-2026-86118 MEDIUM Patched 4.3 2026-09-05 gonic versions before 0.22.0 fail to validate administrator privileges in the startScan endpoint, allowing any authenticated user to trigger media library rescans. Attacker…
CVE-2026-86120 MEDIUM 4.3 2026-09-05 APITable through 1.13.0-beta.1 contains an incorrect authorization vulnerability in NodePermissionGuard that fails to enforce node-level access control when permission look…
CVE-2026-86122 MEDIUM 5.0 2026-09-05 Rowboat through 0.9.1 fails to validate custom MCP server and webhook URLs, allowing authenticated users to configure arbitrary destinations. Attackers can point these URLs…
CVE-2026-86112 MEDIUM 5.4 2026-09-05 BookWyrm through 0.9.1 fails to validate user visibility permissions in the Favorite and Unfavorite views, allowing authenticated attackers to favorite or unfavorite follow…
CVE-2026-86113 MEDIUM 6.5 2026-09-05 BookWyrm through 0.9.1 contains an authorization bypass vulnerability in the edit_readthrough function that allows authenticated users to modify other users' reading record…
CVE-2026-86114 MEDIUM Patched 6.5 2026-09-05 Arcane versions before 2.0.0 fail to properly restrict template operations, allowing default user role accounts to create, modify, and delete compose templates including in…
CVE-2026-86115 MEDIUM Patched 5.0 2026-09-05 Sim before 0.8.14 classifies tool requests as internal based on URL prefix matching without scheme normalization, skipping SSRF validation and minting internal authenticati…
CVE-2026-86116 MEDIUM Patched 6.5 2026-09-05 Metabase versions before 0.63.1 fail to enforce data analyst permission checks on glossary API endpoints, allowing any authenticated user to create, modify, and delete glos…
CVE-2026-86111 MEDIUM 6.5 2026-09-05 BookWyrm through 0.9.1 fails to validate user visibility permissions in the status edit endpoint, allowing authenticated attackers to read followers-only and direct-message…
CVE-2026-76573 MEDIUM 6.4 2026-09-05 The Pods – Custom Content Types and Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'not_found' Shortcode Attribute in all versions up to, and …
CVE-2026-75018 MEDIUM 4.3 2026-09-05 The Custom Contact Forms plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.16. This is due to the plugin not properly verif…
CVE-2026-75586 MEDIUM 6.1 2026-09-05 The Unlimited Elements For Elementor plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via 'formData[id]' Parameter in all versions up to, and including,…
CVE-2026-85414 MEDIUM 6.4 2026-09-05 The Gallery : FooGallery plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'custom_settings' Shortcode Attribute in all versions up to, and including, 3…
CVE-2026-84898 MEDIUM Patched 6.6 2026-09-05 The Eventin WordPress plugin before 4.1.21 does not properly validate a template path value before using it to include a local file, allowing users with contributor-level …
CVE-2026-84899 MEDIUM Patched 6.8 2026-09-05 The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Con…
CVE-2026-84901 MEDIUM Patched 4.9 2026-09-05 The Eventin WordPress plugin before 4.1.22 does not properly check authorization on several of its event-management REST routes, allowing users with contributor-level acce…
CVE-2026-84930 MEDIUM Patched 6.8 2026-09-05 The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery …
CVE-2026-84931 MEDIUM Patched 6.8 2026-09-05 The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, al…
CVE-2026-84936 MEDIUM Patched 5.3 2026-09-05 The EmbedPress WordPress plugin before 4.6.4 does not have proper authorization on a public review-loading action, allowing unauthenticated users to force the site to make…
CVE-2026-84937 MEDIUM Patched 6.8 2026-09-05 The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users wit…
CVE-2026-82846 MEDIUM Patched 6.8 2026-09-05 The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing user…