Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,449 CVEs · Medium severity

CVEs (3,449, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 3,449 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9857 MEDIUM 4.3 2026-07-10 The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that…
CVE-2026-9838 MEDIUM 6.1 2026-07-10 The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due to i…
CVE-2026-9824 MEDIUM Patched 4.3 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, &hellip;
CVE-2026-9799 MEDIUM Patched 4.6 2026-06-25 A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using &hellip;
CVE-2026-9775 MEDIUM Patched 6.5 2026-06-24 ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati&hellip;
CVE-2026-9774 MEDIUM Patched 6.5 2026-06-24 ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected instal&hellip;
CVE-2026-9756 MEDIUM 6.4 2026-07-03 The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an&hellip;
CVE-2026-9738 MEDIUM 4.4 2026-07-11 The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and&hellip;
CVE-2026-9737 MEDIUM 6.5 2026-07-22 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran&hellip;
CVE-2026-9734 MEDIUM 4.3 2026-07-18 The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor&hellip;
CVE-2026-9731 MEDIUM 4.3 2026-07-08 The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce val&hellip;
CVE-2026-9729 MEDIUM 6.4 2026-07-23 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par&hellip;
CVE-2026-9724 MEDIUM 4.3 2026-06-24 The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida&hellip;
CVE-2026-9721 MEDIUM 4.3 2026-06-24 The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre&hellip;
CVE-2026-9718 MEDIUM Patched 6.5 2026-06-25 CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s&hellip;
CVE-2026-9708 MEDIUM Patched 4.9 2026-07-13 Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate that an assigned incoming webhook user has access to the target team or channel&hellip;
CVE-2026-9705 MEDIUM Patched 6.5 2026-06-25 A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerabil&hellip;
CVE-2026-9699 MEDIUM 6.8 2026-06-26 Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail to sanitize error responses from the OpenAI API before logging, which allows a user with access to server l&hellip;
CVE-2026-9677 MEDIUM 4.8 2026-06-27 The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via &hellip;
CVE-2026-9676 MEDIUM Patched 4.3 2026-06-29 The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with S&hellip;
CVE-2026-9656 MEDIUM 4.3 2026-07-17 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.&hellip;
CVE-2026-9651 MEDIUM Patched 4.4 2026-06-25 CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise whe&hellip;
CVE-2026-9639 MEDIUM Patched 6.5 2026-06-26 Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions &hellip;
CVE-2026-9635 MEDIUM 6.4 2026-07-23 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in&hellip;
CVE-2026-9626 MEDIUM 6.4 2026-07-03 The JSON API User plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content' parameter of the post_comment API endpoint in versions up to, and incl&hellip;