CVE search
369,518 resultsCVE-2026-11398MEDIUMLatePoint <= 5.6.1 - Missing Authorization to Unauthenticated Arbitrary Customer Data Modification via process_step_customer() Booking Form Customer StepEPSS 0.3%CVE-2026-4804MEDIUMZakra <= 4.2.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Meta REST APIEPSS 0.2%CVE-2026-9756MEDIUMGenerateBlocks <= 2.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Headline Block 'linkMetaFieldType' Dynamic Link AttributeEPSS 0.2%CVE-2026-11778MEDIUMCURCY <= 2.2.14 - Unauthenticated Arbitrary Shortcode Execution via 'exchange' ParameterEPSS 0.3%CVE-2026-11900MEDIUMAd Inserter <= 2.8.16 - Insecure Direct Object Reference to Authenticated (Contributor+) Arbitrary Post Content Disclosure via 'data' Shortcode AttributeEPSS 0.3%CVE-2026-47896HIGHApache Lucene.Net: Unauthenticated arbitrary file read on the Lucene.Net.Replicator replication serverEPSS 0.7%CVE-2026-47897HIGHApache Lucene.Net: Arbitrary file write from malicious server to Lucene.Net.Replicator clientEPSS 0.6%CVE-2026-47898MEDIUMApache Lucene.Net: XXE vulnerability in Lucene.Net.Analysis.Common PatternParserEPSS 0.3%CVE-2026-8804MEDIUMCleartext Storage of Sensitive Information for Puppet Resource APIEPSS 0.1%CVE-2026-14544CRITICALHplip: incomplete fix for cve-2026-8631EPSS 0.6%CVE-2026-9148HIGHComments <= 7.6.56 - Unauthenticated Stored Cross-Site Scripting via 'Website' FieldEPSS 0.3%CVE-2026-9230MEDIUMQuiz and Survey Master (QSM) <= 11.1.4 - Missing Authorization to Authenticated (Contributor+) Arbitrary Quiz Modification and Email Reroute via Leaked Nonce from /quiz/structureEPSS 0.3%CVE-2026-8351MEDIUMRTMKit <= 2.0.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Advanced Heading Widget 'Background Text' ParameterEPSS 0.2%CVE-2026-9547HIGHSSH improper host validationEPSS 0.5%CVE-2026-9546HIGHsending old refererEPSS 0.7%CVE-2026-9545HIGHexposing HTTP/3 early dataEPSS 0.4%CVE-2026-9080HIGHUAF after pause in socket callbackEPSS 0.5%CVE-2026-9079CRITICALstale proxy password leakEPSS 1.1%CVE-2026-8932HIGHincomplete mTLS config matching in conn reuseEPSS 0.4%CVE-2026-8927CRITICALenv-set cross-proxy Digest auth state leakEPSS 0.8%