Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

790 CVEs · Medium severity

CVEs (790, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 790 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2020-37277 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send s…
CVE-2021-43613 MEDIUM 6.5 2026-09-03 An issue was discovered in SysPasswordDxe in Insyde InsydeH2O. User and administrator password hashes are exposed in runtime UEFI variables, leading to escalation of privilege
CVE-2021-43614 MEDIUM 6.7 2026-09-03 Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.
CVE-2021-48007 MEDIUM Patched 6.5 2026-09-06 PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packet…
CVE-2022-51008 MEDIUM Patched 5.3 2026-09-06 PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers …
CVE-2022-51010 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.4.2 fail to properly validate item IDs received from clients in itemstack NBT data. Attackers can send crafted item IDs outside the valid ra…
CVE-2022-51011 MEDIUM Patched 4.3 2026-09-07 PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large …
CVE-2022-51012 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafte…
CVE-2022-51013 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. Attackers can send negative or out-of-ran…
CVE-2022-51014 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can s…
CVE-2022-51015 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 4.0.6 does not validate facing values in PlayerActionPacket (for START_BREAK and CRACK_BREAK actions) or in UseItemTransactionData (typically within In…
CVE-2022-51016 MEDIUM Patched 6.1 2026-09-07 PocketMine-MP 3.x (before 3.27.0) does not implement Minecraft Bedrock protocol encryption, so the server cannot verify that a connecting client possesses the private key c…
CVE-2022-51018 MEDIUM Patched 6.5 2026-09-07 PocketMine-MP before 3.26.5 and 4.0.x before 4.0.5 does not limit book page text length, page count, or author/title length. A player who obtains a writable book can create…
CVE-2024-3773 MEDIUM 5.9 2026-09-02 The LiveJournal Shortcode WordPress plugin through 1.1.1 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the …
CVE-2025-14945 MEDIUM 5.4 2026-09-05 The Events Manager - Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via event attribute values in all versions up …
CVE-2025-15481 MEDIUM 5.3 2026-09-02 The Notification Bar for WordPress plugin through 1.1.8 exposes an unauthenticated CSV export script that discloses all stored subscriber emails.
CVE-2025-15489 MEDIUM Patched 5.3 2026-09-02 The Passster WordPress plugin before 4.2.24 does not handle input properly in an AJAX action, allowing unauthenticated users to retrieve the value of password protected content
CVE-2025-15490 MEDIUM Patched 5.3 2026-09-02 The Passster WordPress plugin before 4.2.26 has a flaw in its global protection checks, allowing unauthenticated users to bypass the protection offered via crafted URLs
CVE-2025-15613 MEDIUM 6.5 2026-09-01 Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to create Kyverno (Cluster)Polici…
CVE-2025-15647 MEDIUM Patched 5.5 2026-09-05 CDT before 1.4.5 contains an out-of-bounds read vulnerability in the opposedVertexInd() function when constraint edge intersections are computed in floating point and round…
CVE-2025-15663 MEDIUM Patched 6.8 2026-09-02 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's after-label value before its bundled client-side scri…
CVE-2025-15664 MEDIUM Patched 6.8 2026-09-02 The Ultimate Before After Image Slider & Gallery WordPress plugin before 4.7.19 does not properly escape the slider's before-label value before its bundled client-side scr…
CVE-2025-15691 MEDIUM Patched 5.3 2026-09-04 The WPFunnels WordPress plugin before 3.13.0 does not check whether user registration is enabled on the site before creating accounts from opt-in form submissions, relying…
CVE-2025-7963 MEDIUM 6.4 2026-09-02 The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and includ…
CVE-2025-8945 MEDIUM Patched 5.3 2026-09-02 The Wp Edit Password Protected WordPress plugin before 1.3.5 allows protecting page content, but this protection can be bypassed by using the REST API.