Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,682 CVEs · Medium severity

CVEs (3,682, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 3,682 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-86142 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation.
CVE-2026-86143 MEDIUM Patched 6.9 2026-09-05 In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for inte…
CVE-2026-86138 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow.
CVE-2026-86139 MEDIUM Patched 6.9 2026-09-05 In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow.
CVE-2026-55529 MEDIUM Patched 6.9 2026-08-25 PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream _validate_origin method accepts request_origin.startswith(allowed), so the attacker-…
CVE-2026-16938 MEDIUM Patched 6.9 2026-08-19 IBM Power Systems Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 is affected by a vulnerability in access contr…
CVE-2026-8810 MEDIUM 6.9 2026-08-19 On ARM platforms, a vulnerability in the architecture design of HDD Password could allow an attacker to retrieve HDD Password from UEFI variables.
CVE-2026-52873 MEDIUM Patched 6.9 2026-08-18 Streambert is a cross-platform Electron Desktop App to stream and download video content. From version 2.5.0 until version 2.6.0, the wyzie-open-redeem IPC handler in index…
CVE-2026-54570 MEDIUM Patched 6.9 2026-08-18 AngleSharp is a .NET library for parsing angle bracket based hyper-texts. Prior to 1.5.0, MathAnnotationXmlElement in AngleSharp/Mathml/Dom/Internal/MathAnnotationXmlElemen…
CVE-2026-74859 MEDIUM 6.8 2026-09-08 The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files …
CVE-2026-62653 MEDIUM 6.8 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is&hellip;
CVE-2026-62654 MEDIUM 6.8 2026-09-08 A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in &hellip;
CVE-2026-86497 MEDIUM Patched 6.8 2026-09-07 In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials
CVE-2026-86254 MEDIUM 6.8 2026-09-06 wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer c&hellip;
CVE-2026-84028 MEDIUM Patched 6.8 2026-09-06 The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Co&hellip;
CVE-2026-84899 MEDIUM Patched 6.8 2026-09-05 The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Con&hellip;
CVE-2026-84930 MEDIUM Patched 6.8 2026-09-05 The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery &hellip;
CVE-2026-84931 MEDIUM Patched 6.8 2026-09-05 The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, al&hellip;
CVE-2026-84937 MEDIUM Patched 6.8 2026-09-05 The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users wit&hellip;
CVE-2026-82846 MEDIUM Patched 6.8 2026-09-05 The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing user&hellip;
CVE-2026-83544 MEDIUM Patched 6.8 2026-09-05 The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contr&hellip;
CVE-2026-84021 MEDIUM Patched 6.8 2026-09-05 The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded,&hellip;
CVE-2026-84022 MEDIUM Patched 6.8 2026-09-05 The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with&hellip;
CVE-2026-84221 MEDIUM Patched 6.8 2026-09-05 The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to app&hellip;
CVE-2026-84896 MEDIUM Patched 6.8 2026-09-05 The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with&hellip;