87,929 indexed
CVECVE vulnerabilities
87,929 CVEs indexed — newest first. Filter by CVSS severity or CISA KEV listing; KEV-flagged entries surface a rose pill. Authored by Adam Lundqvist.
Showing 1,151–1,200 of 87,929 · page 24 of 1759
| ID | Title | Summary |
|---|---|---|
| CVE-2026-9697 | CVE-2026-9697 CVSS 7.4nodejs | Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection t… |
| CVE-2026-96962 | CVE-2026-96962 CVSS 3.7 | The Pie Register WordPress plugin before 3.8.4.14 does not restrict access to an invitation-code report, allowing unauthenticated visitors who know a valid in… |
| CVE-2026-9695 | CVE-2026-9695 CVSS 9.8 | An Improper Authentication vulnerability affecting DELMIA Apriso from Release 2020 through Release 2026 could allow an attacker to gain privileged access to th… |
| CVE-2026-96940 | CVE-2026-96940 CVSS 8.8 | Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a network. |
| CVE-2026-9694 | CVE-2026-9694 CVSS 2.6gitlab | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain… |
| CVE-2026-9693 | CVE-2026-9693 CVSS 3.5mattermost | Mattermost versions 10.11.x <= 10.11.20, 11.7.x <= 11.7.5 Mattermost fails to remove thread membership records when a user is removed from or leaves a team, wh… |
| CVE-2026-9692 | CVE-2026-9692 CVSS 5.3 | Mojolicious::Sessions::Storable versions through 0.05 for Perl generate session ids insecurely. The default session id generator returns a SHA-1 hash seeded w… |
| CVE-2026-9691 | CVE-2026-9691 CVSS 9.8 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. |
| CVE-2026-96899 | CVE-2026-96899 CVSS 6.8 | The Optima Express IDX WordPress plugin before 8.7.6 does not properly neutralise a script value submitted through one of its REST endpoints before storing it … |
| CVE-2026-96898 | CVE-2026-96898 CVSS 7.3 | A vulnerability was detected in yhx070424 ShopXO up to 2.2.7. Affected by this vulnerability is an unknown functionality of the file config/ueditor.php of the … |
| CVE-2026-96897 | CVE-2026-96897 CVSS 5.3 | The Optima Express IDX WordPress plugin before 8.7.6 does not perform any authorisation check on one of its AJAX actions that is available to logged-out users,… |
| CVE-2026-96896 | CVE-2026-96896 CVSS 7.2 | The Malcure Malware Shield — Removal, Repair, Monitor WordPress plugin before 19.9.7 does not perform an authorisation check on one of its AJAX actions, allowi… |
| CVE-2026-96895 | CVE-2026-96895 CVSS 6.8 | The WP YouTube Lyte WordPress plugin before 1.7.31 does not escape some attributes of YouTube embed blocks before outputting them in an HTML attribute when ren… |
| CVE-2026-96892 | CVE-2026-96892 CVSS 4.3 | A flaw has been found in Edimax BR-6428nC 1.16. The impacted element is the function websRedirect of the component goform Handler. Executing a manipulation of … |
| CVE-2026-96891 | CVE-2026-96891 CVSS 9.8 | A vulnerability was identified in D-Link DIR-825 3.00b32. Affected is the function tunnel_set_params of the file tunnel.c of the component rp-l2tp. The manipul… |
| CVE-2026-96890 | CVE-2026-96890 | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed a repository contributor to cause the appliance to i… |
| CVE-2026-9689 | CVE-2026-9689 CVSS 4.2redhat | A flaw was found in Keycloak, an open-source identity and access management solution. When a client application is configured to accept broad redirect Uniform … |
| CVE-2026-96889 | CVE-2026-96889 CVSS 7.8 | A flaw was found in librsvg. When processing an SVG document containing nested XML inclusions (Xincludes) with duplicate entity declarations, a use-after-free … |
| CVE-2026-96886 | CVE-2026-96886 CVSS 5.3 | The Course Booking System WordPress plugin before 7.0.9 does not restrict access to its booking export, allowing unauthenticated users to download the name, em… |
| CVE-2026-96884 | CVE-2026-96884 CVSS 6.3 | A security flaw has been discovered in MantisZip up to 0.4.5. Affected by this issue is the function Path.Combine of the file MainWindow.UI.cs of the component… |
| CVE-2026-96883 | CVE-2026-96883 CVSS 8.8 | pgcollection is an open source extension to PostgreSQL. A type confusion issue in AWS pgcollection 2.0.0 through 2.1.1 might allow an authenticated remote user… |
| CVE-2026-96882 | CVE-2026-96882 CVSS 5.3 | A vulnerability was identified in TaleLin lin-cms-spring-boot up to 0.2.1. Affected by this vulnerability is the function searchBook of the file src/main/java/… |
| CVE-2026-96881 | CVE-2026-96881 CVSS 5.3 | A vulnerability was determined in TaleLin lin-cms-spring-boot up to 0.2.1. Affected is the function getBooks of the file src/main/java/io/github/talelin/lattic… |
| CVE-2026-96880 | CVE-2026-96880 CVSS 5.3 | A vulnerability was found in TaleLin lin-cms-spring-boot up to 0.2.1. This impacts the function getBook of the file src/main/java/io/github/talelin/latticy/con… |
| CVE-2026-96879 | CVE-2026-96879 | Improper removal of sensitive information before storage or transfer vulnerability in Wikimedia Foundation's Mediawiki - FlaggedRevs extension through 1.46.0. |
| CVE-2026-96878 | CVE-2026-96878 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This i… |
| CVE-2026-96877 | CVE-2026-96877 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This i… |
| CVE-2026-96876 | CVE-2026-96876 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Reflected XSS. This i… |
| CVE-2026-96875 | CVE-2026-96875 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - Cargo extension allows Stored XSS. This iss… |
| CVE-2026-96874 | CVE-2026-96874 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in the Mediawiki - Cargo extension allows Stored XSS. … |
| CVE-2026-96873 | CVE-2026-96873 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Mediawiki - CirrusSearch extension allows Reflected XSS. … |
| CVE-2026-96872 | CVE-2026-96872 | Improper handling of insufficient permissions or privileges vulnerability in The Wikimedia Foundation Mediawiki - WikiLambda Extension on Linux, MacOS, and Win… |
| CVE-2026-96871 | CVE-2026-96871 CVSS 7.2 | The Mang Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'data_type' parameter in all versions up to, and including, 2.4.2 due … |
| CVE-2026-96869 | CVE-2026-96869 CVSS 4.3mozilla | Information disclosure in the Networking component. This vulnerability was fixed in Firefox ESR 153.4, Thunderbird 157, Thunderbird 140.17, Thunderbird 153.4, … |
| CVE-2026-96838 | CVE-2026-96838 CVSS 8.8 | Unauthenticated Cross Site Request Forgery (CSRF) in Blacklist Manager – WooCommerce Anti-Fraud, Blacklist & Checkout Verification <= 2.3.1 versions. |
| CVE-2026-96837 | CVE-2026-96837 CVSS 8.8 | Contributor Remote Code Execution (RCE) in CartFlows <= 3.2.0 versions. |
| CVE-2026-96836 | CVE-2026-96836 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in Parsi Date <= 6.3 versions. |
| CVE-2026-96835 | CVE-2026-96835 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in King Addons for Elementor <= 51.1.85 versions. |
| CVE-2026-96834 | CVE-2026-96834 CVSS 6.5 | Subscriber Sensitive Data Exposure in GiveWP <= 4.16.9 versions. |
| CVE-2026-96833 | CVE-2026-96833 CVSS 7.2 | Editor PHP Object Injection in Ultimate Addons for Contact Form 7 <= 3.5.51 versions. |
| CVE-2026-96832 | CVE-2026-96832 CVSS 7.2 | Shop manager PHP Object Injection in Content Egg <= 6.3.1 versions. |
| CVE-2026-96831 | CVE-2026-96831 CVSS 8.8 | Contributor PHP Object Injection in Themify Builder <= 7.8.1 versions. |
| CVE-2026-96830 | CVE-2026-96830 CVSS 7.1 | Unauthenticated Cross Site Scripting (XSS) in GiveWP <= 4.16.9 versions. |
| CVE-2026-96829 | CVE-2026-96829 CVSS 6.5 | Contributor Cross Site Scripting (XSS) in The Plus Addons for Elementor Page Builder Lite <= 6.5.1 versions. |
| CVE-2026-96828 | CVE-2026-96828 CVSS 7.6 | Administrator SQL Injection in Category Discount Woocommerce <= 5.18 versions. |
| CVE-2026-96827 | CVE-2026-96827 CVSS 7.6 | Administrator SQL Injection in Admin Notices Manager <= 1.6.0 versions. |
| CVE-2026-96826 | CVE-2026-96826 CVSS 7.6 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Shazzad Hossain Khan W4 Post List allows Blind SQL Inject… |
| CVE-2026-96825 | CVE-2026-96825 CVSS 4.2 | Subscriber Bypass Vulnerability in All In One WP Security & Firewall <= 5.4.8 versions. |
| CVE-2026-96824 | CVE-2026-96824 CVSS 6.8 | Editor Arbitrary File Deletion in Template Kit – Import <= 1.0.16 versions. |
| CVE-2026-96823 | CVE-2026-96823 CVSS 7.5 | Unauthenticated Arbitrary Content Deletion in Customer Reviews for WooCommerce <= 5.120.0 versions. |