Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

790 CVEs · Medium severity

CVEs (790, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 790 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86150 MEDIUM 4.1 2026-09-05 A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument …
CVE-2026-83543 MEDIUM Patched 4.1 2026-09-05 The Greenshift WordPress plugin before 13.2.0 does not validate a user-supplied URL before fetching it server-side, allowing users with contributor-level access and above …
CVE-2026-82186 MEDIUM Patched 4.1 2026-09-04 The WPLP Cookie Consent WordPress plugin before 4.4.2 does not properly validate a pagination parameter before using it in a SQL query, allowing users with administrator p…
CVE-2026-74768 MEDIUM 4.1 2026-09-03 Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Server-Side Request Forgery (SSRF) vulnerability in the REST API. A high privileged remote attacker c…
CVE-2026-16647 MEDIUM 4.1 2026-09-02 Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Disable Login Page allows Functionality Bypass. This issue affects Disable Login Page versi…
CVE-2026-82182 MEDIUM Patched 4.1 2026-09-02 The WPvivid — Backup, Migration & Staging WordPress plugin before 0.9.133 does not sanitise a user supplied list of identifiers before using it in a SQL query, allowing adm…
CVE-2026-84962 MEDIUM 4.2 2026-09-03 An unauthorized user with key vault write access may cause an authorized client to issue arbitrary authenticated Google Cloud KMS API calls under the authorized user's iden…
CVE-2026-84657 MEDIUM 4.2 2026-09-02 In Jenkins 2.579 and earlier, LTS 2.568.2 and earlier, the build CLI command does not check the Item/Cancel permission when using the -s flag to cancel a build triggered to…
CVE-2026-84358 MEDIUM Patched 4.2 2026-09-02 Improper privilege management in Downloads in Google Chrome prior to 152.0.7977.75 allowed a remote attacker who had compromised the renderer process to spoof address bar v…
CVE-2026-78606 MEDIUM Patched 4.2 2026-09-01 Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized disclosure, modification, and deletion of data via Accessing Functionality Not Properly Constrained by …
CVE-2026-86515 MEDIUM 4.3 2026-09-08 A security vulnerability has been detected in vgmstream up to r2117. Impacted is the function add_entry of the file src/meta/txtp_parser.c of the component txtp. Such manip…
CVE-2026-76963 MEDIUM 4.3 2026-09-08 Due to a missing authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform, an authenticated attacker could gain unauthorized access to sensitive sy…
CVE-2026-76977 MEDIUM 4.3 2026-09-08 SAP UI5 does not sufficiently validate the parent frame's origin against the configured allowlist. An unauthenticated attacker could host a malicious page to bypass framing…
CVE-2026-76962 MEDIUM 4.3 2026-09-08 SAP S/4HANA (Manage Bank Chains app) does not perform sufficient authorization checks within certain affected functionality. An attacker with low privileges could send spec…
CVE-2026-86499 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
CVE-2026-86496 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.2.18769 missing access control on Helpdesk authorized reporters exposed reporter email addresses
CVE-2026-86481 MEDIUM Patched 4.3 2026-09-07 In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons
CVE-2026-86307 MEDIUM 4.3 2026-09-07 A security vulnerability has been detected in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. This vulnerability affects un…
CVE-2022-51011 MEDIUM Patched 4.3 2026-09-07 PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large …
CVE-2026-86294 MEDIUM 4.3 2026-09-07 A vulnerability has been found in SourceCodester Simple Traffic Offense System 1.0. Affected by this issue is some unknown functionality of the file save-settings.php of th…
CVE-2026-86285 MEDIUM 4.3 2026-09-07 A vulnerability was detected in BookStack up to 26.05.2. Affected by this issue is the function AttachmentController::getUpdateForm of the file app/Uploads/Controllers/Atta…
CVE-2026-86289 MEDIUM 4.3 2026-09-07 A vulnerability was found in Ollama up to 0.31.1. This issue affects the function readGGUFV1String of the file fs/ggml/gguf.go of the component GGUF Decoder. Performing a m…
CVE-2026-86281 MEDIUM 4.3 2026-09-07 A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipula…
CVE-2026-86278 MEDIUM 4.3 2026-09-07 A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file manage_su…
CVE-2026-86264 MEDIUM 4.3 2026-09-07 A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/…