Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

907 CVEs · Medium severity

CVEs (907, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 907 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9737 MEDIUM 6.5 2026-07-22 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran…
CVE-2026-9734 MEDIUM 4.3 2026-07-18 The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor…
CVE-2026-9729 MEDIUM 6.4 2026-07-23 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par…
CVE-2026-9656 MEDIUM 4.3 2026-07-17 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.…
CVE-2026-9635 MEDIUM 6.4 2026-07-23 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in…
CVE-2026-9602 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to &hellip;
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?&hellip;
CVE-2026-9537 MEDIUM Patched 5.3 2026-07-17 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom&hellip;
CVE-2026-9066 MEDIUM Patched 6.1 2026-07-23 The WP Compress WordPress plugin before 7.10.04 does not validate the value of a query parameter that controls the asset CDN host before using it to build the URLs of Java&hellip;
CVE-2026-8861 MEDIUM 5.3 2026-07-17 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser.  This information coul&hellip;
CVE-2026-8825 MEDIUM Patched 4.9 2026-07-20 The Elementor Website Builder WordPress plugin before 4.1.4 does not properly check user permissions before returning post data through one of its REST endpoints, allowing&hellip;
CVE-2026-8616 MEDIUM 5.3 2026-07-17 The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the &hellip;
CVE-2026-8287 MEDIUM 4.3 2026-07-23 Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software allows Excessive&hellip;
CVE-2026-8285 MEDIUM 4.3 2026-07-21 Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Excessive Allocation. This issue affects FlexCity: from &hellip;
CVE-2026-8284 MEDIUM 6.1 2026-07-21 URL redirection to untrusted site ('open redirect') vulnerability in Universal Software Inc. FlexCity allows Input Data Manipulation. This issue affects FlexCity: from 5.5&hellip;
CVE-2026-8075 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 5.5.13 6.0.2.0 fail to properly null check when checking for headers in the Mattermost Desktop App which allows any user to crash anot&hellip;
CVE-2026-7771 MEDIUM 5.5 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to a denial &hellip;
CVE-2026-7120 MEDIUM Patched 5.3 2026-07-23 @fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the pathname used for file resolution. Versions up to an&hellip;
CVE-2026-6793 MEDIUM Patched 5.4 2026-07-20 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bifra Engineering Consulting Ltd. Q-smart NexT Poll allows Stored XSS.&hellip;
CVE-2026-6792 MEDIUM 6.5 2026-07-21 Missing Authorization vulnerability in Universal Software Inc. FlexCity allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects FlexCit&hellip;
CVE-2026-65920 MEDIUM Patched 4.3 2026-07-23 Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_files function that allows attackers to read arbitra&hellip;
CVE-2026-65913 MEDIUM Patched 6.1 2026-07-23 DOMPurify before 3.3.2 contains a prototype pollution vulnerability in USE_PROFILES mode that allows attackers to bypass attribute filtering by polluting Array.prototype pr&hellip;
CVE-2026-65912 MEDIUM Patched 6.1 2026-07-23 DOMPurify before 3.3.2 contains a URI validation bypass vulnerability when ADD_ATTR is provided as a predicate function via EXTRA_ELEMENT_HANDLING.attributeCheck. Attackers&hellip;
CVE-2026-65911 MEDIUM 6.1 2026-07-23 In DOMPurify through 3.3.3, function predicates supplied via ADD_ATTR or ADD_TAGS to DOMPurify.sanitize() persist in internal state (EXTRA_ELEMENT_HANDLING) across subseque&hellip;
CVE-2026-65904 MEDIUM 4.7 2026-07-23 DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a different window/realm (e.g., an iframe's contentDocument&hellip;