Search
790 CVEs · Medium severity
CVEs (790, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 790 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86142 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, there is a heap-based buffer overflow in xmlXPtrEvalXPtrPart because of xmlXPtrEval xpointer length saturation. |
| CVE-2026-86143 | MEDIUM | Patched | 6.9 | 2026-09-05 | In xmlIO in libxml2 before 2.15.4, an inconsistency in xmlOutputWriteCallback and xmlBufUse causes negative lengths to reach write callbacks, aka a lack of a check for inte… |
| CVE-2026-86138 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlDictAddQString in dict.c has an integer overflow and resultant heap-based buffer overflow. |
| CVE-2026-86139 | MEDIUM | Patched | 6.9 | 2026-09-05 | In libxml2 before 2.15.4, xmlURIEscapeStr in uri.c has an integer overflow. |
| CVE-2026-74859 | MEDIUM | 6.8 | 2026-09-08 | The shell theme installer in gnome-tweaks extracts user-supplied ZIP archives without validating archive member paths. As a result, a crafted theme archive can write files … | |
| CVE-2026-62653 | MEDIUM | 6.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). The input received over a proprietary communication protocol that is exposed when the device is… | |
| CVE-2026-62654 | MEDIUM | 6.8 | 2026-09-08 | A vulnerability has been identified in Reyrolle 7SR5 (All versions < V2.70). A special maintenance mode can be activated via a physical key sequence during device boot, in … | |
| CVE-2026-86497 | MEDIUM | Patched | 6.8 | 2026-09-07 | In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials |
| CVE-2026-86254 | MEDIUM | 6.8 | 2026-09-06 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer c… | |
| CVE-2026-84028 | MEDIUM | Patched | 6.8 | 2026-09-06 | The Bold Page Builder WordPress plugin before 5.9.9 does not sanitise and escape a shortcode attribute before outputting it in an HTML attribute, allowing users with the Co… |
| CVE-2026-84899 | MEDIUM | Patched | 6.8 | 2026-09-05 | The VikWidgetsLoader WordPress plugin before 1.12.0 does not sanitise or escape a block attribute before outputting it inside an inline script, allowing users with the Con… |
| CVE-2026-84930 | MEDIUM | Patched | 6.8 | 2026-09-05 | The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not properly validate a block attribute before using it as an HTML tag name in its gallery … |
| CVE-2026-84931 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Joli Table Of Contents WordPress plugin before 3.0.3 does not sanitise or escape a shortcode attribute value before outputting it inside an HTML element's attribute, al… |
| CVE-2026-84937 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users wit… |
| CVE-2026-82846 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Masteriyo LMS WordPress plugin before 3.4.0 does not sanitise and escape some course settings before outputting them in a page available to all visitors, allowing user… |
| CVE-2026-83544 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Greenshift WordPress plugin before 13.2.0 does not properly escape a block animation attribute before outputting it within an HTML attribute, allowing users with contr… |
| CVE-2026-84021 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Bold Page Builder WordPress plugin before 5.9.8 does not properly validate a link URL before outputting it in an HTML attribute, relying on a filter that can be evaded,… |
| CVE-2026-84022 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Bold Page Builder WordPress plugin before 5.9.8 does not sanitise and escape several shortcode attributes before outputting them in HTML attributes, allowing users with… |
| CVE-2026-84221 | MEDIUM | Patched | 6.8 | 2026-09-05 | The Kirki WordPress plugin before 6.3.0 does not escape a user-supplied identifier before using it in a SQL query, allowing users with editor-level access and above to app… |
| CVE-2026-84896 | MEDIUM | Patched | 6.8 | 2026-09-05 | The King Addons for Elementor WordPress plugin before 51.1.77 does not escape a widget display-style setting before outputting it in an HTML attribute, allowing users with… |
| CVE-2026-61608 | MEDIUM | 6.8 | 2026-09-04 | SolidInvoice is an open-source invoicing platform. Prior to version 3.0.1, `UserInvitation` entities have no expiry timestamp. Invitation links mailed to users remain valid… | |
| CVE-2026-74853 | MEDIUM | Patched | 6.8 | 2026-09-04 | The Pods WordPress plugin before 3.3.9.2 does not restrict which functions a display callback may resolve to, allowing users with the author role and above to read arbitra… |
| CVE-2026-80253 | MEDIUM | 6.8 | 2026-09-03 | An improper physical access control issue exists in ShizenBox2 (dev-conf). If exploited, an attacker with physical access to the product may execute bootloader commands wit… | |
| CVE-2026-68860 | MEDIUM | 6.8 | 2026-09-03 | Dell PowerProtect Data Manager, versions 20.2.0.0 and below, contain a Reliance on Data/Memory Layout vulnerability. An unauthenticated remote attacker could potentially ex… | |
| CVE-2026-55421 | MEDIUM | 6.8 | 2026-09-02 | Open edX Platform enables the authoring and delivery of online learning at any scale. Prior to commit 00b7c3c, the endpoint accepts user-supplied files[].url, performs a se… |