Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,163 CVEs

CVEs (3,163, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 3,163 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-9833 HIGH Patched 7.1 2026-07-20 The Tag Groups is the Advanced Way to Display Your Taxonomy Terms WordPress plugin before 2.2.0 does not properly escape one of its AJAX parameters before reflecting it in …
CVE-2026-9810 CRITICAL Patched 9.8 2026-07-17 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut…
CVE-2026-9762 HIGH 7.8 2026-07-17 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control.
CVE-2026-9737 MEDIUM 6.5 2026-07-22 During query planning when reading the sort pattern in raw BSONObj form, in some places we don’t explicitly handle the meta expression case. This may lead to incorrect tran…
CVE-2026-9734 MEDIUM 4.3 2026-07-18 The W3SC Elementor to Zoho CRM plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.2.0. This is due to missing or incor…
CVE-2026-9729 MEDIUM 6.4 2026-07-23 The Webpushr Push Notifications plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'webpushr_notification_title' and 'webpushr_notification_body' par…
CVE-2026-9713 HIGH 7.5 2026-07-23 The Lumise Product Designer for WooCommerce plugin for WordPress is vulnerable to SQL Injection via the 'id' and 'table' parameters in the uploaded cart JSON file processed…
CVE-2026-9656 MEDIUM 4.3 2026-07-17 The HubSpot All-In-One Marketing – Forms, Popups, Live Chat plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 11.3.…
CVE-2026-9635 MEDIUM 6.4 2026-07-23 The WP Shortcode by MyThemeShop plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'title' parameter of the [tab] shortcode in versions up to, and in…
CVE-2026-9602 MEDIUM 6.5 2026-07-17 Mattermost Desktop App versions <=6.2 6.0.2 5.6.13.0 fail to validate payloads sent from the Mattermost Web App to the Desktop App which allows a malicious server owner to &hellip;
CVE-2026-9592 NONE &mdash; 2026-07-17 SEPPmail Secure Email Gateway & SEPPmail Cloud before version 15.0.4.2 allows an attacker to replay & hijack a user session in the GINA web portal, as the session token is &hellip;
CVE-2026-9588 NONE &mdash; 2026-07-17 A stored cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997) within the voicemail notification template functionality. The submit_&hellip;
CVE-2026-9587 NONE &mdash; 2026-07-17 An authenticated local file inclusion vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The play_file functionality accepts user-controlled input through &hellip;
CVE-2026-9586 NONE &mdash; 2026-07-17 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> &hellip;
CVE-2026-9585 NONE &mdash; 2026-07-17 An unauthenticated reflected cross-site scripting (XSS) vulnerability exists in Sangoma Switchvox SMB Edition version 8.3 (104997). The application fails to properly saniti&hellip;
CVE-2026-9577 MEDIUM Patched 4.8 2026-07-23 The Post Status Notifier Lite WordPress plugin before 1.13.0 does not properly escape the `mod` URL parameter before reflecting it into the admin settings page (`admin.php?&hellip;
CVE-2026-9537 MEDIUM Patched 5.3 2026-07-17 Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recom&hellip;
CVE-2026-9499 NONE &mdash; 2026-07-21 An out-of-bounds read (buffer over-read) vulnerability exists in QTextCodec::codecForName() in Qt. When the function is called with a QByteArray that is not NUL-terminated &hellip;
CVE-2026-9323 HIGH 8.1 2026-07-18 The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that &hellip;
CVE-2026-9202 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented &hellip;
CVE-2026-9198 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code&hellip;
CVE-2026-9171 HIGH 7.5 2026-07-17 IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause the s&hellip;
CVE-2026-9147 HIGH 7.8 2026-07-18 uproot dynamically generates Python class source code from ROOT TStreamerInfo records in a file and compiles it at runtime. Some file-controlled streamer metadata fields (f&hellip;
CVE-2026-9135 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies&hellip;
CVE-2026-9103 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The&hellip;