Search
31,862 CVEs
CVEs (31,862, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 31,862 (capped at 500)
| CVE ID ↑ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2011-10043 | CRITICAL | Patched | 9.8 | 2026-07-07 | Module::Load versions before 0.22 for Perl allow arbitrary modules outside of @INC to be loaded. Module names starting with "::" could be passed to the load function to sp… |
| CVE-2016-20066 | HIGH | 7.2 | 2026-06-15 | WordPress CP Polls 1.0.8 contains a persistent cross-site scripting vulnerability that allows attackers to inject malicious scripts through unsanitized file upload function… | |
| CVE-2016-20067 | MEDIUM | 4.3 | 2026-06-15 | WordPress CP Polls 1.0.8 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions on behalf of authenticated users. Attacke… | |
| CVE-2016-20068 | HIGH | 8.2 | 2026-06-15 | WordPress Booking Calendar Contact Form version 1.0.23 contains an unauthenticated blind SQL injection vulnerability that allows remote attackers to execute arbitrary SQL q… | |
| CVE-2016-20069 | HIGH | 8.2 | 2026-06-15 | WordPress Booking Calendar Contact Form 1.0.23 contains an unauthenticated blind SQL injection vulnerability in the shortcode function that fails to sanitize the calendar p… | |
| CVE-2016-20070 | MEDIUM | 6.4 | 2026-06-15 | WordPress Booking Calendar Contact Form 1.0.23 contains privilege escalation and stored cross-site scripting vulnerabilities that allow authenticated users to modify plugin… | |
| CVE-2016-20071 | HIGH | 8.2 | 2026-06-15 | The 404 Redirection Manager plugin version 1.0 for WordPress contains an unauthenticated SQL injection vulnerability that allows remote attackers to execute arbitrary SQL q… | |
| CVE-2016-20072 | HIGH | 8.2 | 2026-06-15 | BBS e-Franchise 1.1.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malic… | |
| CVE-2016-20073 | HIGH | 8.2 | 2026-06-15 | Answer My Question 1.3 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting mali… | |
| CVE-2016-20074 | MEDIUM | 4.3 | 2026-06-15 | WordPress Lazy Content Slider Plugin 3.4 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by crafting malicious HTM… | |
| CVE-2016-20075 | HIGH | 8.8 | 2026-06-15 | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated users with contributor, editor, author, or administrator … | |
| CVE-2016-20076 | HIGH | 7.5 | 2026-06-15 | WordPress Simple-Backup 2.7.11 contains multiple vulnerabilities that allow unauthenticated attackers to delete arbitrary files and download sensitive files by manipulating… | |
| CVE-2016-20077 | MEDIUM | 6.2 | 2026-06-15 | WordPress Plugin Photocart Link 1.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting insufficient i… | |
| CVE-2016-20078 | MEDIUM | 6.2 | 2026-06-15 | WordPress IMDb Profile Widget 1.0.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the url para… | |
| CVE-2016-20079 | MEDIUM | 6.2 | 2026-06-15 | WordPress Dharma Booking 2.28.3 and earlier contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating t… | |
| CVE-2016-20080 | MEDIUM | 6.2 | 2026-06-15 | WordPress Brandfolder plugin version 3.0 and earlier contains a local file inclusion vulnerability in callback.php that allows unauthenticated attackers to include arbitrar… | |
| CVE-2016-20081 | HIGH | 7.5 | 2026-06-15 | WordPress Plugin HB Audio Gallery Lite 1.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the f… | |
| CVE-2016-20082 | MEDIUM | 6.2 | 2026-06-15 | WordPress Plugin Abtest contains a local file inclusion vulnerability that allows unauthenticated attackers to include arbitrary files by manipulating the action parameter.… | |
| CVE-2016-20083 | MEDIUM | 5.3 | 2026-06-15 | WordPress More Fields Plugin 2.1 contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized actions by disabling CSRF token validatio… | |
| CVE-2016-20084 | HIGH | 7.2 | 2026-06-15 | WordPress appointment-booking-calendar 1.1.24 contains multiple privilege escalation vulnerabilities that allow unauthenticated attackers to modify calendar settings and in… | |
| CVE-2016-20085 | HIGH | 7.8 | 2026-06-19 | Realtek High Definition Audio Driver 6.0.1.6730 contains an unquoted service path vulnerability that allows local attackers to escalate privileges by placing a malicious ex… | |
| CVE-2016-20086 | HIGH | 7.8 | 2026-06-19 | Vembu StoreGrid 4.0 contains an unquoted service path vulnerability in the RemoteBackup and RemoteBackup_webServer services that allows local attackers to escalate privileg… | |
| CVE-2016-20087 | HIGH | 7.8 | 2026-06-19 | Fortitude HTTP 1.0.4.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with elevated privileges by exploiting the service … | |
| CVE-2016-20088 | HIGH | 7.8 | 2026-06-19 | Comodo Chromodo Browser 52.15.25.664 contains an unquoted service path vulnerability in the ChromodoUpdater service that runs with SYSTEM privileges. A local attacker can i… | |
| CVE-2016-20089 | HIGH | 7.8 | 2026-06-19 | Iperius Remote 1.7.0 contains an unquoted service path vulnerability that allows local users to execute arbitrary code with SYSTEM privileges by exploiting the service inst… |