Search
3,163 CVEs
EOL hidden · Show all products
CVEs (3,163, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,163 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9833 | HIGH | Patched | 7.1 | 2026-07-20 | The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in … |
| CVE-2026-9810 | CRITICAL | Patched | 9.8 | 2026-07-17 | The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut… |
| CVE-2026-9762 | HIGH | 7.8 | 2026-07-17 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-9734 | MEDIUM | 4.3 | 2026-07-18 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor… | |
| CVE-2026-9729 | MEDIUM | 6.4 | 2026-07-23 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par… | |
| CVE-2026-9713 | HIGH | 7.5 | 2026-07-23 | The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed… | |
| CVE-2026-9656 | MEDIUM | 4.3 | 2026-07-17 | The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.… | |
| CVE-2026-9635 | MEDIUM | 6.4 | 2026-07-23 | The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in… | |
| CVE-2026-9602 | MEDIUM | 6.5 | 2026-07-17 | Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to … | |
| CVE-2026-9592 | NONE | — | 2026-07-17 | SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is … | |
| CVE-2026-9588 | NONE | — | 2026-07-17 | A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_… | |
| CVE-2026-9587 | NONE | — | 2026-07-17 | An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through … | |
| CVE-2026-9586 | NONE | — | 2026-07-17 | An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> … | |
| CVE-2026-9585 | NONE | — | 2026-07-17 | An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti… | |
| CVE-2026-9577 | MEDIUM | Patched | 4.8 | 2026-07-23 | The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?… |
| CVE-2026-9537 | MEDIUM | Patched | 5.3 | 2026-07-17 | Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom… |
| CVE-2026-9499 | NONE | — | 2026-07-21 | An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated … | |
| CVE-2026-9323 | HIGH | 8.1 | 2026-07-18 | The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that … | |
| CVE-2026-9202 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented … | |
| CVE-2026-9198 | CRITICAL | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code… | |
| CVE-2026-9171 | HIGH | 7.5 | 2026-07-17 | IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the s… | |
| CVE-2026-9147 | HIGH | 7.8 | 2026-07-18 | uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f… | |
| CVE-2026-9135 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies… |
| CVE-2026-9103 | CRITICAL | Patched | 9.8 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The… |