Search
26,633 CVEs · Medium severity
CVEs (26,633, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 26,633 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2025-0765 | MEDIUM | Patched | 4.3 | 2025-07-24 | An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthori… |
| CVE-2025-1299 | MEDIUM | Patched | 4.3 | 2025-07-24 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting f… |
| CVE-2025-4393 | MEDIUM | 6.5 | 2025-07-24 | Medtronic MyCareLink Patient Monitor has an internal service that deserializes data, which allows a local attacker to interact with the service by crafting a binary payload… | |
| CVE-2025-4394 | MEDIUM | 6.8 | 2025-07-24 | Medtronic MyCareLink Patient Monitor uses an unencrypted filesystem on internal storage, which allows an attacker with physical access to read and modify files. This issu… | |
| CVE-2025-4395 | MEDIUM | 6.8 | 2025-07-24 | Medtronic MyCareLink Patient Monitor has a built-in user account with an empty password, which allows an attacker with physical access to log in with no password and access… | |
| CVE-2025-4968 | MEDIUM | Patched | 6.4 | 2025-07-24 | The WPBakery Page Builder for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple Page Builder elements (Copyright Element, Hover Box,… |
| CVE-2025-4976 | MEDIUM | Patched | 4.3 | 2025-07-24 | An issue has been discovered in GitLab EE affecting all versions from 17.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under certain circumstances, coul… |
| CVE-2025-7001 | MEDIUM | Patched | 4.3 | 2025-07-24 | An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged … |
| CVE-2025-7745 | MEDIUM | 5.8 | 2025-07-24 | Buffer Over-read vulnerability in ABB AC500 V2.This issue affects AC500 V2: through 2.5.2. | |
| CVE-2025-8009 | MEDIUM | 4.9 | 2025-07-24 | The Security Ninja – WordPress Security Plugin & Firewall plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 5.242 via the 'get… | |
| CVE-2025-8107 | MEDIUM | 6.3 | 2025-07-24 | In OceanBase's Oracle tenant mode, a malicious user with specific privileges can achieve privilege escalation to SYS-level access by executing carefully crafted commands. … | |
| CVE-2025-3669 | MEDIUM | 6.4 | 2025-07-24 | The Supreme Addons for Beaver Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's auto_qrcodesabb shortcode in all versions up to, an… | |
| CVE-2025-4608 | MEDIUM | 6.4 | 2025-07-24 | The Structured Content plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sc_fs_local_business shortcode in all versions up to, and includin… | |
| CVE-2025-5084 | MEDIUM | Patched | 6.1 | 2025-07-24 | The Post Grid Master plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘argsArray['read_more_text']’ parameter in all versions up to, and includi… |
| CVE-2025-6262 | MEDIUM | 6.4 | 2025-07-24 | The muse.ai video embedding plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's muse-ai shortcode in all versions up to, and including, 0.4 d… | |
| CVE-2025-6382 | MEDIUM | 6.4 | 2025-07-24 | The Taeggie Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's taeggie-feed shortcode in all versions up to, and including, 0.1.10. The… | |
| CVE-2025-6385 | MEDIUM | 6.4 | 2025-07-24 | The WP Applink plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘title’ parameter in all versions up to, and including, 0.4.1 due to insufficient i… | |
| CVE-2025-6387 | MEDIUM | 6.4 | 2025-07-24 | The WP Get The Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 1.5 due to insufficient… | |
| CVE-2025-6539 | MEDIUM | 6.4 | 2025-07-24 | The Voltax Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘id’ parameter in all versions up to, and including, 1.6.5 due to insuffic… | |
| CVE-2025-6588 | MEDIUM | 6.1 | 2025-07-24 | The FunnelCockpit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘error’ parameter in all versions up to, and including, 1.4.3 due to insuffic… | |
| CVE-2025-7690 | MEDIUM | 6.1 | 2025-07-24 | The Affiliate Plus plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.2. This is due to missing or incorrect nonce v… | |
| CVE-2025-7780 | MEDIUM | 6.5 | 2025-07-24 | The AI Engine plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.9.4. The simpleTranscribeAudio endpoint fails to … | |
| CVE-2025-7822 | MEDIUM | 4.3 | 2025-07-24 | The WP Wallcreeper plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the admin_notices hook in all versions up to… | |
| CVE-2025-7835 | MEDIUM | 4.3 | 2025-07-24 | The iThoughts Advanced Code Editor plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.2.10. This is due to missing or … | |
| CVE-2025-7959 | MEDIUM | 6.4 | 2025-07-24 | The Station Pro plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘width' and 'height’ parameter in all versions up to, and including, 2.4.2 due to … |