Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

1,463 CVEs

EOL hidden · Show all products

CVEs (1,463, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 1,463 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-10301 MEDIUM 4.3 2026-06-02 A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of the…
CVE-2026-10302 MEDIUM 6.3 2026-06-02 A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation of the a…
CVE-2026-10514 LOW 2.4 2026-06-02 A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestPar…
CVE-2026-10528 LOW 3.3 2026-06-02 A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/F…
CVE-2026-9048 MEDIUM 4.3 2026-06-02 The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it …
CVE-2026-9050 MEDIUM 4.3 2026-06-02 The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not prope…
CVE-2026-10529 LOW 2.4 2026-06-02 A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/m…
CVE-2026-10548 MEDIUM 5.3 2026-06-02 A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/cr…
CVE-2026-10550 MEDIUM 6.3 2026-06-02 A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment Module. Thi…
CVE-2026-10558 MEDIUM 6.3 2026-06-02 A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the …
CVE-2026-10559 MEDIUM 6.3 2026-06-02 A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation of the ar…
CVE-2026-10100 MEDIUM 4.4 2026-06-02 The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, …
CVE-2026-10510 MEDIUM 6.1 2026-06-02 Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows re…
CVE-2026-10565 LOW 3.1 2026-06-02 A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component NGAP …
CVE-2026-10566 MEDIUM 5.3 2026-06-02 A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a …
CVE-2026-10567 LOW 3.5 2026-06-02 A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/Module…
CVE-2026-10568 MEDIUM 6.3 2026-06-02 A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument I…
CVE-2026-3722 MEDIUM 6.4 2026-06-02 The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via th…
CVE-2026-3870 MEDIUM 6.5 2026-06-02 A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to tr…
CVE-2026-3871 MEDIUM 6.5 2026-06-02 A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to…
CVE-2026-10581 MEDIUM 6.3 2026-06-02 A flaw has been found in DedeCMS 5.7.88. Affected by this vulnerability is the function base64_decode of the file /plus/download.php?open=1. This manipulation of the argume…
CVE-2026-10583 MEDIUM 4.7 2026-06-02 A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. Affected by this issue is the function Import of the file internal/http/tts_config.go of…
CVE-2026-3198 MEDIUM 6.5 2026-06-02 MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HA…
CVE-2026-8206 CRITICAL 9.8 2026-06-02 The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions 6.0.0 to 6.0…
CVE-2026-8293 HIGH Patched 7.5 2026-06-02 The Really Simple Security WordPress plugin before 9.5.10.1 does not enforce the second-factor challenge in two of its two-factor authentication REST endpoints, allowing a…