Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

790 CVEs · Medium severity

CVEs (790, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 1–25 of 790 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-67395 MEDIUM 5.9 2026-09-01 A path traversal vulnerability exists in Sage Employee Self Service’s custom logo functionality due to improper validation of file path parameters. By leveraging directory …
CVE-2026-19032 MEDIUM Patched 5.3 2026-09-01 jackson-databind's deserializer for java.nio.file.Path resolves an attacker-supplied URI without restricting the URI scheme. In JDKFromStringDeserializer.NioPathHelper.dese…
CVE-2026-12747 MEDIUM 6.4 2026-09-01 The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tag' Shortcode Attribute in all versions up to, and including, 3.29.…
CVE-2026-13203 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_id' shortcode attribute of the dslc_mod…
CVE-2026-16787 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'dslc_custom_field' Shortcode in all versions up to…
CVE-2026-17589 MEDIUM 4.9 2026-09-01 The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to generic SQL Injection via the 'product_order' parameter in all versions up to, and including, 5.9.…
CVE-2026-18752 MEDIUM 6.5 2026-09-01 The Persistent Login plugin for WordPress is vulnerable to generic SQL Injection via 'wppl_device_id' Cookie in all versions up to, and including, 3.1.0 due to insufficient…
CVE-2026-19948 MEDIUM 5.3 2026-09-01 The Cozy Blocks – Page Builder for Gutenberg Editor & FSE with 700+ Patterns, 58 Blocks & Templates plugin for WordPress is vulnerable to authorization bypass in all versio…
CVE-2026-75965 MEDIUM 6.4 2026-09-01 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'date' …
CVE-2026-76006 MEDIUM 4.9 2026-09-01 The Photo Gallery by Ays – Responsive Image Gallery plugin for WordPress is vulnerable to generic SQL Injection via the 's' parameter in all versions up to, and including, …
CVE-2026-77823 MEDIUM 4.9 2026-09-01 The LearnPress plugin for WordPress is vulnerable to SQL Injection via the 'orderby' parameter of the export_order_csv AJAX action in versions up to, and including, 4.4.4. …
CVE-2026-83743 MEDIUM 6.3 2026-09-01 A weakness has been identified in invoiceninja Invoice Ninja up to 5.13.26. This affects an unknown part of the file /vedor/profile/ of the component Vendor Portal Profile …
CVE-2026-83744 MEDIUM 4.3 2026-09-01 A security vulnerability has been detected in invoiceninja Invoice Ninja up to 5.13.26. This vulnerability affects the function Purify::isHostSafe of the file app/Services/…
CVE-2026-18488 MEDIUM 6.4 2026-09-01 The Blocksy Companion plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'tagName' Block Attribute (blocksy/dynamic-data) in all versions up to, and incl…
CVE-2026-75964 MEDIUM 6.1 2026-09-01 The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'em…
CVE-2026-75980 MEDIUM 6.4 2026-09-01 The BetterDocs – AI Documentation, Knowledge Base, Docs, Wikis, FAQ with Chatbot plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Heading 'id' Attribut…
CVE-2026-77189 MEDIUM 6.5 2026-09-01 The Charitable – Donation & Fundraising Platform (Donation Forms, Recurring Donations & Fundraising Campaigns) plugin for WordPress is vulnerable to generic SQL Injection v…
CVE-2026-13611 MEDIUM Patched 5.3 2026-09-01 The KiviCare WordPress plugin before 4.5.5 does not perform authorization checks on some of its REST endpoints, allowing unauthenticated attackers to disclose the patient r…
CVE-2026-74916 MEDIUM Patched 6.5 2026-09-01 The WP Fastest Cache WordPress plugin before 1.5.1 does not include a set of tracking-related query parameters in its page-cache key while still caching pages requested wit…
CVE-2026-78363 MEDIUM Patched 4.8 2026-09-01 The MW WP Form WordPress plugin before 5.1.5 does not prevent shortcodes in user-submitted values from being executed when it merges those values into a message that it lat…
CVE-2026-15101 MEDIUM 6.4 2026-09-01 The WPBakery Page Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data' parameter in all versions up to, and including, 8.7.4 due to insu…
CVE-2026-16786 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_testimonials_output Shortcode in all ve…
CVE-2026-16788 MEDIUM 6.4 2026-09-01 The Live Composer – Free WordPress Website Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dslc_module_projects_output Shortcode in all versio…
CVE-2026-82926 MEDIUM 5.5 2026-09-01 NULL pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before afef59aa6f55c5d5ebf9b14bc020bf1c2c37489a.
CVE-2026-82927 MEDIUM Patched 5.5 2026-09-01 Untrusted pointer dereference vulnerability in Samsung Open Source mTower allows Pointer Manipulation. This issue affects mTower: before 06994e303637512e39062f3e037c222e8448e57e.