Search
9,751 CVEs · Medium severity
CVEs (9,751, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 9,751 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9859 | MEDIUM | Patched | 6.5 | 2026-08-17 | Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles on the channelId field of the batch endpoint, which a… |
| CVE-2026-9857 | MEDIUM | 4.3 | 2026-07-10 | The Invoice123 plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.7.0. This is due to the plugin not properly verifying that… | |
| CVE-2026-9838 | MEDIUM | 6.1 | 2026-07-10 | The ICS Calendar plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'htmltagtitle' parameter in all versions up to, and including, 12.0.9 due to i… | |
| CVE-2026-9824 | MEDIUM | Patched | 4.3 | 2026-07-13 | Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to check the manage_shared_channels permission in the /share-channel autocomplete handler, … |
| CVE-2026-9822 | MEDIUM | Patched | 6.5 | 2026-06-19 | The WP Hotel Booking WordPress plugin before 2.3.1 does not enforce capability checks in several of its AJAX handlers, allowing authenticated users with Subscriber-level ac… |
| CVE-2026-9815 | MEDIUM | 6.5 | 2026-06-18 | The MagicForm WordPress plugin through 0.1.3 does not properly validate the type of files uploaded through an unauthenticated AJAX action when a form's per-field extension … | |
| CVE-2026-9799 | MEDIUM | Patched | 4.6 | 2026-06-25 | A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permission ticket for one resource can exploit this by using … |
| CVE-2026-9775 | MEDIUM | Patched | 6.5 | 2026-06-24 | ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installati… |
| CVE-2026-9774 | MEDIUM | Patched | 6.5 | 2026-06-24 | ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected instal… |
| CVE-2026-9770 | MEDIUM | Patched | 5.3 | 2026-07-15 | Kasa EC71 v4 and EC70 v4 firmware contains a static cryptographic private key stored in a read-only filesystem that is shared across devices. An attacker with access to th… |
| CVE-2026-9767 | MEDIUM | 6.5 | 2026-08-16 | The The School Management – Education & Learning ERP plugin for WordPress is vulnerable to generic SQL Injection via 'order[0][dir]' Parameter in all versions up to, and in… | |
| CVE-2026-9756 | MEDIUM | 6.4 | 2026-07-03 | The GenerateBlocks plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link Attribute in all versions up to, an… | |
| CVE-2026-9745 | MEDIUM | 6.5 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This om… | |
| CVE-2026-9744 | MEDIUM | 5.3 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitiv… | |
| CVE-2026-9738 | MEDIUM | 4.4 | 2026-07-11 | The Print, PDF, Email by PrintFriendly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'content_position_css' parameter in all versions up to, and… | |
| CVE-2026-9737 | MEDIUM | 6.5 | 2026-07-22 | During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran… | |
| CVE-2026-9736 | MEDIUM | 5.3 | 2026-09-03 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements w… | |
| CVE-2026-9734 | MEDIUM | 4.3 | 2026-07-18 | The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor… | |
| CVE-2026-9731 | MEDIUM | 4.3 | 2026-07-08 | The Wp Js Detect plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.9. This is due to missing or incorrect nonce val… | |
| CVE-2026-9729 | MEDIUM | 6.4 | 2026-07-23 | The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par… | |
| CVE-2026-9728 | MEDIUM | 6.4 | 2026-08-24 | The userspace syscall verifier z_vrfy_mbox_send() in drivers/mbox/mbox_handlers.c validated the nested msg->data/msg->size fields by reading them directly out of live users… | |
| CVE-2026-9724 | MEDIUM | 4.3 | 2026-06-24 | The MotorDesk plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.2. This is due to missing or incorrect nonce valida… | |
| CVE-2026-9721 | MEDIUM | 4.3 | 2026-06-24 | The Book a Room Event Calendar plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.9. This is due to missing or incorre… | |
| CVE-2026-9720 | MEDIUM | 4.3 | 2026-07-29 | The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.0.2. This is due to missing … | |
| CVE-2026-9718 | MEDIUM | Patched | 6.5 | 2026-06-25 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a s… |