Alle sårbarheter
Hele katalogen, nyeste først. Filtrer, sorter og bla gjennom den. Skal du søke opp et bestemt produkt, gjøres det fortsatt fra søkesiden.
Hurtigvalg: Nyeste Aktivt utnyttede Kritiske Mest sannsynlig utnyttet
124 101 sårbarheter · side 1 av 40
| CVE | Tittel | Alvorlighet | EPSS | Publisert |
|---|---|---|---|---|
| CVE-2026-90788 | magicblack MacCMS10 Template .%40template%40default%40html%40label.html os command injection | Middels 5.1 | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-82439 | Apache Storm DRPC: Unauthenticated Unbounded Memory Growth in DRPC | Uten score | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-82920 | Mattermost ABAC parent policy bypass via policy update endpoint | Middels 5.5 | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-82441 | Apache Storm Nimbus: Cross-Tenant Blob Deletion and Cluster Denial of Service via Unvalidated Topology Depend… | Uten score | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-84179 | Apache Storm Nimbus, Apache Storm UI: Disclosure of Unredacted Merged Daemon Configuration via the Topology P… | Uten score | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-86348 | MS Calendar plugin: unrecovered handler panics from malformed post-action requests could crash the plugin pro… | Middels 4.3 | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-86349 | Mattermost Server Algorithmic DoS via Unbounded Markdown Block Nesting | Middels 4.3 | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-90961 | MISP LdapAuth and LinOTPAuth Authentication Bypass via Empty or Non-String Credentials | Kritisk 9.3 | Ikke tilgjengelig | 2026-09-14 |
| CVE-2026-90616 | In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on th… | Høy 7.4 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90560 | zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictDecompress | Høy 8.8 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90559 | snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress | Høy 8.7 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90558 | sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers | Kritisk 9.3 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90557 | Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame | Middels 6.9 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90556 | Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load | Høy 8.5 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-15451 | The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up … | Høy 8.8 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-10148 | The Booking for Appointments and Events Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scri… | Middels 6.4 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90474 | MCPHub before 1.0.32 OAuth 2.0 Authentication Bypass | Høy 7.6 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90473 | msgpack-java through 0.9.12 Integer Overflow via MAP32 | Middels 6.9 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-90472 | msgpack-java through 0.9.12 Stack Overflow via Nested Arrays | Middels 6.9 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-85200 | The GEO my WP plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including… | Høy 7.5 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-85198 | The MPG – Multiple Page Generator, Bulk Landing Pages & Programmatic SEO plugin for WordPress is vulnerable t… | Middels 6.5 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-78175 | The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to PHP Object Injecti… | Høy 8.8 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-78159 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, an… | Kritisk 9.8 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-78006 | The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, an… | Kritisk 9.8 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-77161 | The Smart Marketing SMS and Newsletters Forms plugin for WordPress is vulnerable to generic SQL Injection via… | Middels 6.5 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-17585 | The Royal Addons for Elementor – Addons and Templates Kit for Elementor plugin for WordPress is vulnerable to… | Middels 5.3 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-16482 | The rtMedia for WordPress, BuddyPress and bbPress plugin for WordPress is vulnerable to time-based blind SQL … | Høy 7.5 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-11355 | The DT LMS – elearning, WordPress LMS plugin for WordPress is vulnerable to unauthorized modification of data… | Middels 5.3 | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-87842 | Zonify < 1.0.5 - Unauthenticated Account Login Token Disclosure | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-87797 | Client Invoicing by Sprout Invoices < 20.8.16 - Subscriber+ Private Note Overwrite via si_edit_private_note | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-87759 | Add User Autocomplete < 1.2 - Subscriber+ Privilege Escalation | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-86790 | WP Highlight Box <= 1.0 - Contributor+ Stored XSS via highlight-box Shortcode | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-85681 | WP Component <= 2.2.4 - Unauthenticated Privilege Escalation via Arbitrary Blog Option Update | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-84171 | WP Images Upload on Piclect <= 1.0 - Unauthenticated Arbitrary File Upload | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-84099 | IDB Ecommerce (wpStoreCart 5) <= 5.0.7 - Unauthenticated PHP Object Injection via bundled wpsc-membership-pro… | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-84047 | Album Cover Finder <= 0.7.0 - Unauthenticated SQLi via and_action | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-84025 | BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Authenticated Product Download… | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-84024 | BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Meta Field Configuration Updat… | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-84023 | BEAR - Bulk Editor and Products Manager Professional for WooCommerce < 1.2.2 - Taxonomy Term Modification via… | Uten score | Ikke tilgjengelig | 2026-09-12 |
| CVE-2026-82851 | Masteriyo LMS 1.14.0 - 3.4.0 - Instructor+ Arbitrary Post Disclosure via IDOR | Uten score | Ikke tilgjengelig | 2026-09-12 |
En strek under EPSS betyr at anslaget ikke er publisert ennå. EPSS regnes ut etter at sårbarheten er registrert, så de aller ferskeste oppføringene mangler det gjerne et døgn eller to.
Blaingen stopper her. Snevre inn filtrene for å nå eldre oppføringer: å bla gjennom tusenvis av sider er tregere enn å filtrere, og til mindre nytte.