Search
907 CVEs · Medium severity
CVEs (907, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 1–25 of 907 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↑ | Description |
|---|---|---|---|---|---|
| CVE-2026-33434 | MEDIUM | Patched | 4.3 | 2026-07-17 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 4.6.0 and above, prior to 4.14.5, a logic error in CheckRateLimits… |
| CVE-2026-33754 | MEDIUM | Patched | 6.5 | 2026-07-17 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.9.0 and above, prior to 4.14.5, a remote attacker can trigger me… |
| CVE-2026-2594 | MEDIUM | Patched | 6.4 | 2026-07-17 | The Smart Custom Fields plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 5.0.7. This is due to insufficient input sanitiz… |
| CVE-2026-40106 | MEDIUM | Patched | 4.7 | 2026-07-17 | Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above prior to 4.14.5 contain a heap-based buffer overflow … |
| CVE-2026-44251 | MEDIUM | Patched | 6.5 | 2026-07-17 | Wazuh is a free and open source platform used for threat prevention, detection, and response. In versions 3.0.0 and above, prior to 4.14.5, a size_t integer underflow in os… |
| CVE-2026-62208 | MEDIUM | Patched | 6.5 | 2026-07-17 | OpenClaw before 2026.6.5 could forward Authorization headers during MCP SSE redirects. When the affected feature is enabled and reachable, a lower-trust caller or configure… |
| CVE-2026-62210 | MEDIUM | Patched | 6.5 | 2026-07-17 | OpenClaw versions before 2026.6.1 contain a denial of service vulnerability where remote media URLs can trigger slow-read attacks that exhaust gateway worker resources. Att… |
| CVE-2026-62211 | MEDIUM | Patched | 5.0 | 2026-07-17 | OpenClaw versions before 2026.6.1 contain a credential redaction bypass vulnerability in the trajectory export feature that allows lower-trust callers to access data that s… |
| CVE-2026-62213 | MEDIUM | Patched | 6.5 | 2026-07-17 | OpenClaw versions before 2026.5.27 contain a token leakage vulnerability in MS Teams outbound requests that allows lower-trust callers to expose Bot Framework tokens. Attac… |
| CVE-2026-62214 | MEDIUM | Patched | 6.5 | 2026-07-17 | OpenClaw versions before 2026.5.28 Bot Framework contains an improper input validation vulnerability that allows lower-trust callers to expose bot tokens and credentials by… |
| CVE-2026-62216 | MEDIUM | Patched | 5.0 | 2026-07-17 | OpenClaw 2026.4.20 before 2026.5.28 contain a policy bypass in the QQBot media upload feature. A lower-trust caller or configured input path could cause the media upload to… |
| CVE-2026-62220 | MEDIUM | Patched | 5.3 | 2026-07-17 | OpenClaw 2026.2.25 before 2026.5.26 allow a lower-trust caller or configured input path to bypass non-browser rate limits on WebSocket authentication attempts. When the aff… |
| CVE-2026-62221 | MEDIUM | Patched | 5.4 | 2026-07-17 | OpenClaw 2026.5.12 before 2026.5.26 contain an incorrect authorization vulnerability in the ClickClack allowFrom feature. When the affected feature is enabled and reachable… |
| CVE-2026-62224 | MEDIUM | Patched | 5.4 | 2026-07-17 | OpenClaw MS Teams before 2026.5.12 contain an authorization bypass vulnerability where the allowFrom feature binds to mutable display names. Attackers with lower-trust acce… |
| CVE-2026-62225 | MEDIUM | Patched | 5.4 | 2026-07-17 | OpenClaw versions before 2026.5.18 contain an authorization bypass vulnerability in skill command dispatch that allows lower-trust callers to execute or persist actions bey… |
| CVE-2026-62235 | MEDIUM | 6.3 | 2026-07-17 | Grav Flex-Objects before version 1.4.3 contains a broken access control vulnerability in the admin-next REST API that allows authenticated users with only api.access permis… | |
| CVE-2026-62236 | MEDIUM | Patched | 5.4 | 2026-07-17 | grav-plugin-login before 3.8.11 contains a cross-site request forgery (CSRF) vulnerability in the login.regenerate2FASecret frontend task, which regenerates and persists a … |
| CVE-2026-62237 | MEDIUM | Patched | 6.5 | 2026-07-17 | Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content … |
| CVE-2026-11324 | MEDIUM | 6.1 | 2026-07-17 | The WooCommerce Placetopay Gateway and PlacetoPay/AvalPay gateway plugins for WordPress are vulnerable to Reflected Cross-Site Scripting via the 'redirect-url' parameter in… | |
| CVE-2026-15159 | MEDIUM | 4.3 | 2026-07-17 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 3.3.6 via the 'spreadsheet_expor… | |
| CVE-2026-15160 | MEDIUM | 4.3 | 2026-07-17 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 3.3.6 via the 'spreadsheet_export_tmp_name' p… | |
| CVE-2026-8616 | MEDIUM | 5.3 | 2026-07-17 | The Fense Proxy & VPN Blocker plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check and missing nonce validation on the … | |
| CVE-2026-14503 | MEDIUM | 6.5 | 2026-07-17 | The pCloud WP Backup plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.0.3 via the wp2pcl_ajax_process_request_in… | |
| CVE-2026-15161 | MEDIUM | 6.4 | 2026-07-17 | The Ninja Forms - Excel Export plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 3.3.6. This is due to the save_filter() A… | |
| CVE-2026-15349 | MEDIUM | 4.3 | 2026-07-17 | The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.17.6. … |