Search
3,702 CVEs · Medium severity
CVEs (3,702, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 3,702 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↑ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-81680 | MEDIUM | Patched | 4.0 | 2026-08-27 | openssl_encrypt versions before 1.4.9 fail to authenticate recovery-slot presence in envelope-format encrypted files, allowing attackers to remove recovery slots without re… |
| CVE-2026-80213 | MEDIUM | Patched | 4.0 | 2026-08-27 | An issue was discovered in the resolv gem before 0.7.2 for Ruby. Resolv::DNS::MessageEncoder wrote a DNS label's length into a single octet without checking its range. A la… |
| CVE-2026-75421 | MEDIUM | 4.0 | 2026-08-25 | aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function. | |
| CVE-2026-39113 | MEDIUM | 4.0 | 2026-08-25 | Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3ad0c7a1e818da66f106951d496b05cbe61d12c2c448f2f24b6d5d… | |
| CVE-2026-76367 | MEDIUM | Patched | 4.0 | 2026-08-19 | In Splunk SOAR versions below 8.6.0, a user who holds the "Incident Commander" Splunk SOAR role could store JavaScript in a note and run it in the browser of another user w… |
| CVE-2026-70916 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easil… | |
| CVE-2026-70917 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easil… | |
| CVE-2026-70719 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Easily… | |
| CVE-2026-62584 | MEDIUM | 4.0 | 2026-08-18 | Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and Configuration). The supported version that is affec… | |
| CVE-2026-50126 | MEDIUM | 4.0 | 2026-08-18 | Adaguc-server is an open source geographical information system to visualize, combine, compare and share real-time meteorological, climatological and remote sensing data vi… | |
| CVE-2026-58560 | MEDIUM | 4.0 | 2026-08-17 | Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | |
| CVE-2026-58561 | MEDIUM | 4.0 | 2026-08-17 | Null pointer dereference issue in the image codec module. Impact: Successful exploitation of this vulnerability may affect availability. | |
| CVE-2026-71390 | MEDIUM | Patched | 4.0 | 2026-08-11 | CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerabil… |
| CVE-2026-86150 | MEDIUM | 4.1 | 2026-09-05 | A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument … | |
| CVE-2026-83543 | MEDIUM | Patched | 4.1 | 2026-09-05 | The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above … |
| CVE-2026-82186 | MEDIUM | Patched | 4.1 | 2026-09-04 | The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator p… |
| CVE-2026-74768 | MEDIUM | 4.1 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker c… | |
| CVE-2026-16647 | MEDIUM | Patched | 4.1 | 2026-09-02 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versi… |
| CVE-2026-82182 | MEDIUM | Patched | 4.1 | 2026-09-02 | The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing adm… |
| CVE-2026-80488 | MEDIUM | Patched | 4.1 | 2026-08-29 | The WP Ultimate CSV Importer WordPress plugin before 9.0 does not properly sanitise and escape imported field values before using them in a SQL statement, which could allo… |
| CVE-2026-21808 | MEDIUM | 4.1 | 2026-08-26 | HCL BigFix Quantum Risk Analyzer generates highly detailed logging information by default which increases the risk of sensitive data leakage and can provide an attacker wit… | |
| CVE-2026-63466 | MEDIUM | Patched | 4.1 | 2026-08-21 | Unleash is an open-source feature management platform. Prior to 8.0.3, FeatureEventFormatterMd.format in src/lib/addons/feature-event-formatter-md.ts assigns Mustache.escap… |
| CVE-2026-54681 | MEDIUM | Patched | 4.1 | 2026-08-21 | DiscordChatExporter saves Discord chat logs to a file. Prior to 2.47.2, the VisitEmojiAsync method in DiscordChatExporter.Core/Exporting/HtmlMarkdownVisitor.cs interpolates… |
| CVE-2026-70714 | MEDIUM | 4.1 | 2026-08-18 | Vulnerability in the Oracle Hyperion Calculation Manager product of Oracle Hyperion (component: Security). The supported version that is affected is 11.2.25.0.000. Diffic… | |
| CVE-2026-18348 | MEDIUM | 4.1 | 2026-08-11 | Missing authorization check in the upload_azure, upload_sftp, and upload_smb VQL plugins allows an authenticated analyst-role user can initiate attacker-controlled outbound… |